Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-03-13 CVE-2018-1000070 Code Injection vulnerability in Bitmessage Pybitmessage 0.6.2
Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file src/messagetypes/__init__.py function constructObject that can result in Code Execution.
network
low complexity
bitmessage CWE-94
8.8
2018-02-25 CVE-2018-7466 Code Injection vulnerability in Testlink
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.
network
high complexity
testlink CWE-94
7.5
2018-02-22 CVE-2018-6488 Code Injection vulnerability in Microfocus Ucmdb Configuration Manager 4.10/4.11/4.12
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12.
network
low complexity
microfocus CWE-94
critical
9.8
2018-02-21 CVE-2018-7271 Code Injection vulnerability in Metinfo 6.0.0
An issue was discovered in MetInfo 6.0.0.
network
high complexity
metinfo CWE-94
8.1
2018-02-19 CVE-2017-16670 Code Injection vulnerability in Smartbear Soapui 5.3.0
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
local
low complexity
smartbear CWE-94
7.8
2018-02-12 CVE-2018-6889 Code Injection vulnerability in Typesettercms Typesetter 5.1
An issue was discovered in Typesetter 5.1.
network
low complexity
typesettercms CWE-94
8.8
2018-02-07 CVE-2018-6574 Code Injection vulnerability in multiple products
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
local
low complexity
golang debian redhat CWE-94
7.8
2018-01-09 CVE-2018-2363 Code Injection vulnerability in SAP products
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice.
network
low complexity
sap CWE-94
8.8
2018-01-05 CVE-2017-16905 Code Injection vulnerability in Duolingo Tinycards
The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in-the-middle attack.
network
high complexity
duolingo CWE-94
8.1
2018-01-03 CVE-2017-1000480 Code Injection vulnerability in Smarty
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.
network
low complexity
smarty CWE-94
critical
9.8