Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-08-19 CVE-2019-15224 Code Injection vulnerability in Rest-Client Project Rest-Client
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
network
low complexity
rest-client-project CWE-94
critical
9.8
2019-08-14 CVE-2019-0343 Code Injection vulnerability in SAP Commerce Cloud
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection.
network
low complexity
sap CWE-94
8.8
2019-08-13 CVE-2015-9298 Code Injection vulnerability in Pixelite Events Manager
The events-manager plugin before 5.6 for WordPress has code injection.
network
low complexity
pixelite CWE-94
critical
9.8
2019-08-12 CVE-2019-14965 Code Injection vulnerability in Frappe
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4.
network
low complexity
frappe CWE-94
critical
9.8
2019-08-07 CVE-2019-14746 Code Injection vulnerability in Kuaifan Kuaifancms 5.0
A issue was discovered in KuaiFanCMS 5.0.
network
low complexity
kuaifan CWE-94
critical
9.8
2019-08-05 CVE-2017-18468 Code Injection vulnerability in Cpanel
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
network
low complexity
cpanel CWE-94
6.3
2019-08-02 CVE-2019-7871 Code Injection vulnerability in Magento
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code.
network
low complexity
magento CWE-94
8.8
2019-08-01 CVE-2018-20931 Code Injection vulnerability in Cpanel
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
network
low complexity
cpanel CWE-94
6.3
2019-08-01 CVE-2019-0193 Code Injection vulnerability in multiple products
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter.
network
low complexity
apache debian CWE-94
7.2
2019-08-01 CVE-2018-20896 Code Injection vulnerability in Cpanel
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
local
low complexity
cpanel CWE-94
3.9