CVEbaza.plSłownik CWECWE-94
Common Weakness Enumeration

CWE-94

Improper Control of Generation of Code ('Code Injection')

Kategoria: BaseCVE: 7409
Opis

Produkt konstruuje całość lub część segmentu kodu używając danych wejściowych ze źródła zewnętrznego, ale nie neutralizuje lub nieprawidłowo neutralizuje elementy specjalne, które mogą zmienić składnię lub zachowanie zamierzonego segmentu kodu. Umożliwia to atakującemu zmodyfikowanie logiki programu poprzez wprowadzenie złośliwego kodu.

Description (EN)

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Podatności CVE z CWE-94 (7409)
10.0
CVSS
CRITICAL
CVE-2026-18885

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-6876

ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-76604

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

pub. 2026-08-22
10.0
CVSS
CRITICAL
CVE-2026-76605

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

pub. 2026-08-22
10.0
CVSS
CRITICAL
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.

pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

pub. 2026-08-18
10.0
CVSS
CRITICAL
CVE-2026-74253

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

pub. 2026-08-17
10.0
CVSS
CRITICAL
CVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code, achieving full OS command execution as the user running the desktop application and enabling access to SSH keys, stored credentials, and environment secrets.

pub. 2026-08-14
10.0
CVSS
CRITICAL
CVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

pub. 2026-08-13
10.0
CVSS
CRITICAL
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

pub. 2026-08-13
10.0
CVSS
CRITICAL
CVE-2026-67282

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

pub. 2026-08-12
10.0
CVSS
CRITICAL
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.

pub. 2026-08-12
10.0
CVSS
CRITICAL
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

pub. 2026-08-11
10.0
CVSS
CRITICAL
CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

pub. 2026-08-11
10.0
CVSS
CRITICAL
CVE-2026-66915

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

pub. 2026-08-10
10.0
CVSS
CRITICAL
CVE-2026-65553

Krytyczna podatność typu Remote Code Execution (RCE) w pluginie Spider Analyser dla WordPress pozwala nieuwierzytelnionemu atakującemu na zdalne wykonanie dowolnego kodu na serwerze. Uzyskanie pełnej kontroli nad serwerem jest możliwe bez jakichkolwiek poświadczeń dostępu.

pub. 2026-08-06
10.0
CVSS
CRITICAL
CVE-2026-64633

Podatność umożliwia zdalnemu, nieuwierzytelnionemu napastnikowi wykonanie dowolnego kodu na hoście agenta Veeam. Otrzymała maksymalną ocenę CVSS 10.0, co klasyfikuje ją jako podatność krytyczną wymagającą natychmiastowej reakcji.

pub. 2026-08-04
10.0
CVSS
CRITICAL
CVE-2026-65880

Rozszerzenie Balbooa Forms (wersje poniżej 2.4.3) dla systemu Joomla zawiera krytyczną podatność umożliwiającą nieuwierzytelnione zdalne wykonanie kodu (RCE). Atakujący bez żadnych uprawnień może wykonać dowolny kod na serwerze poprzez formularz zawierający pole typu podpis (signature field).

pub. 2026-07-28
10.0
CVSS
CRITICAL
CVE-2025-71389

Cal.com (calcom/cal.diy) w wersjach przed 5.9.9 zawiera podatną wersję Next.js, której mechanizm obsługi żądań React Server Components deserializuje dane kontrolowane przez atakującego. Podatność umożliwia nieuwierzytelnionemu zdalnemu atakującemu wykonanie dowolnego kodu na serwerze bez jakiejkolwiek interakcji użytkownika, co czyni ją wyjątkowo krytyczną.

pub. 2026-07-23
10.0
CVSS
CRITICAL
CVE-2026-47668

DbGate w wersjach 7.1.8 i wcześniejszych umożliwia nieautoryzowane zdalne wykonanie kodu (RCE) poprzez wstrzyknięcie kodu w parametrze `functionName` endpointu `POST /runners/start`. Podatność nie wymaga żadnego uwierzytelnienia, a jej krytyczność (CVSS 10.0) czyni ją natychmiastowym zagrożeniem dla każdej wystawionej na sieć instancji.

pub. 2026-07-23
Pokazano 20 z 7409 podatności
Informacje
ID: CWE-94
Typ: Base
Podatności: 7409
MITRE CWE ↗
← Słownik CWE