Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-38967 Code Injection vulnerability in IBM MQ Appliance 9.2.0.0
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code.
local
low complexity
ibm CWE-94
6.7
2021-11-30 CVE-2021-3725 Code Injection vulnerability in Planetargon OH MY ZSH
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names.
network
low complexity
planetargon CWE-94
8.8
2021-11-22 CVE-2021-33493 Code Injection vulnerability in Open-Xchange OX APP Suite 7.10.5
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
local
low complexity
open-xchange CWE-94
6.0
2021-11-19 CVE-2021-22053 Code Injection vulnerability in VMWare Spring Cloud Netflix
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates.
network
low complexity
vmware CWE-94
8.8
2021-11-13 CVE-2021-41653 Code Injection vulnerability in Tp-Link Tl-Wr840N Firmware
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
network
low complexity
tp-link CWE-94
critical
9.8
2021-11-10 CVE-2021-33816 Code Injection vulnerability in Dolibarr Erp/Crm 13.0.2
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
network
low complexity
dolibarr CWE-94
critical
9.8
2021-11-09 CVE-2021-43466 Code Injection vulnerability in Thymeleaf 3.0.12
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
network
low complexity
thymeleaf CWE-94
critical
9.8
2021-11-05 CVE-2021-41228 Code Injection vulnerability in Google Tensorflow
TensorFlow is an open source platform for machine learning.
local
low complexity
google CWE-94
7.8
2021-11-04 CVE-2021-42057 Code Injection vulnerability in Obsidian Dataview
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.
local
low complexity
obsidian CWE-94
7.8
2021-11-04 CVE-2021-43281 Code Injection vulnerability in Mybb
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission.
network
low complexity
mybb CWE-94
7.2