Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2023-51387 Code Injection vulnerability in Dromara Hertzbeat
Hertzbeat is an open source, real-time monitoring system.
network
low complexity
dromara CWE-94
8.8
2023-12-19 CVE-2023-49004 Code Injection vulnerability in Dlink Dir-850L Firmware Fw223Wwb01
An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.
network
low complexity
dlink CWE-94
critical
9.8
2023-12-18 CVE-2023-6691 Code Injection vulnerability in Cambiumnetworks Epmp Force 300-25 Firmware 4.7.0.1
Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.
local
low complexity
cambiumnetworks CWE-94
7.8
2023-12-18 CVE-2023-32728 Code Injection vulnerability in Zabbix Zabbix-Agent2
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
network
low complexity
zabbix CWE-94
critical
9.8
2023-12-17 CVE-2023-6899 Code Injection vulnerability in Rmountjoy92 Dashmachine 0.54
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4.
network
low complexity
rmountjoy92 CWE-94
critical
9.8
2023-12-17 CVE-2023-6886 Code Injection vulnerability in Wang.Market Wangmarket 6.1
A vulnerability was found in xnx3 wangmarket 6.1.
network
low complexity
wang-market CWE-94
critical
9.8
2023-12-16 CVE-2023-6851 Code Injection vulnerability in Kodcloud Kodexplorer
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03.
network
low complexity
kodcloud CWE-94
critical
9.8
2023-12-15 CVE-2023-50721 Code Injection vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-94
8.8
2023-12-15 CVE-2023-50723 Code Injection vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-94
8.8
2023-12-15 CVE-2023-5512 Code Injection vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2.
network
low complexity
gitlab CWE-94
5.7