Cwe 94

🧬 CWE Related 84
slug: cwe-94

Explanation

CWE-94は「攻撃者が送ったデータが、プログラムコードとして解釈・実行されてしまう」欠陥です。 Pythonの `eval()`・PHPの `eval()`/`include()` にユーザー入力を渡すような実装が典型例です。 リモートコード実行 (RCE) の直接的な原因となるため、最も重大なクラスの脆弱性です。
📌 Example
Log4Shell (CVE-2021-44228) はLog4jのJNDI Lookupを悪用したコードインジェクションで、世界中のJavaサーバーが数日でハッキングされた。

🔖 Related tags

🛡 Vulnerabilities tagged with this 1,130

ID Title
CVE-2024-9050 Code Injection in privilege-escalation (CVE-2024-9050)
CVE-2023-31493 Code Injection in zoneminder (CVE-2023-31493)
CVE-2024-45874 Code Injection in CVE-2024-45874 (CVE-2024-45874)
CVE-2024-45873 Code Injection in CVE-2024-45873 (CVE-2024-45873)
CVE-2024-45933 Code Injection in CVE-2024-45933 (CVE-2024-45933)
CVE-2024-7104 Code Injection in sfs (CVE-2024-7104)
CVE-2024-43469 Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-41623 Code Injection in d3dsecurity (CVE-2024-41623)
CVE-2024-40495 Code Injection in linksys (CVE-2024-40495)
CVE-2024-23692 KEV [KEV] Vulnerability in Rejetto http-file-server (CVE-2024-23692)
CVE-2022-24816 KEV [KEV] Code Injection in Osgeo jai-ext (CVE-2022-24816)
CVE-2024-5683 Code Injection in CVE-2024-5683 (CVE-2024-5683)
CVE-2024-37821 Code Injection in dolibarr (CVE-2024-37821)
CVE-2024-31823 Code Injection in ecommerce-codeigniter-bootstrap-project (CVE-2024-31823)
CVE-2024-20359 KEV [KEV] Code Injection in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2024-20359)
CVE-2024-28699 Code Injection in CVE-2024-28699 (CVE-2024-28699)
CVE-2024-29477 Code Injection in dolibarr (CVE-2024-29477)
CVE-2023-24955 KEV [KEV] Code Injection in Microsoft sharepoint-server (CVE-2023-24955)
CVE-2024-28386 Code Injection in home-made (CVE-2024-28386)
CVE-2021-44529 KEV [KEV] Code Injection in Ivanti endpoint-manager-cloud-service-appliance-epm-csa (CVE-2021-44529)
CVE-2024-24520 Code Injection in lepton-cms (CVE-2024-24520)
CVE-2024-21378 Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-21351 KEV [KEV] Code Injection in Microsoft windows (CVE-2024-21351)
CVE-2024-24396 Cross-Site Scripting (XSS) in stimulsoft (CVE-2024-24396)
CVE-2024-22899 Code Injection in vinchin (CVE-2024-22899)
CVE-2024-1015 Code Injection in se-elektronic (CVE-2024-1015)
CVE-2023-36177 Code Injection in badaix (CVE-2023-36177)
CVE-2023-6548 KEV [KEV] Code Injection in Citrix netscaler-adc-and-netscaler-gateway (CVE-2023-6548)
CVE-2023-46987 Code Injection in seacms (CVE-2023-46987)
CVE-2023-48192 Code Injection in totolink (CVE-2023-48192)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →