Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-43466 Code Injection vulnerability in Thymeleaf 3.0.12
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
network
low complexity
thymeleaf CWE-94
critical
9.8
2021-11-05 CVE-2021-41228 Code Injection vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-94
7.8
2021-11-04 CVE-2021-42057 Code Injection vulnerability in Obsidian Dataview
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.
local
low complexity
obsidian CWE-94
7.8
2021-11-04 CVE-2021-43281 Code Injection vulnerability in Mybb
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission.
network
low complexity
mybb CWE-94
7.2
2021-11-02 CVE-2021-42754 Code Injection vulnerability in Fortinet Forticlient
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
local
low complexity
fortinet CWE-94
5.0
2021-11-01 CVE-2021-25877 Code Injection vulnerability in Youphptube
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write.
network
low complexity
youphptube CWE-94
7.2
2021-11-01 CVE-2021-40348 Code Injection vulnerability in multiple products
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection.
network
low complexity
uyuni-project spacewalk-project CWE-94
8.8
2021-11-01 CVE-2021-42574 Code Injection vulnerability in multiple products
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.
network
high complexity
unicode fedoraproject starwindsoftware CWE-94
8.3
2021-10-28 CVE-2021-36985 Code Injection vulnerability in Huawei Emui and Magic UI
There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.
network
low complexity
huawei CWE-94
7.5
2021-10-27 CVE-2021-41619 Code Injection vulnerability in Gradle Enterprise 2020.4
An issue was discovered in Gradle Enterprise before 2021.1.2.
network
low complexity
gradle CWE-94
7.2