Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-32801 Loading a malicious hook library can lead to local privilege escalation — Kea 7.8 High2025-05-28
CVE-2025-5151 defog-ai introspect analysis_tools.py execute_analysis_code_safely code injection — introspect 5.3 Medium2025-05-25
CVE-2025-5137 DedeCMS Incomplete Fix CVE-2018-9175 sys_verifies.php code injection — DedeCMS 4.7 Medium2025-05-25
CVE-2024-13952 Remote Code Execution — ASPECT-Enterprise 8.4 High2025-05-22
CVE-2024-13929 Authenticated Servlet Command Injection — ASPECT-Enterprise 7.2 High2025-05-22
CVE-2024-13928 Authenticated SQL Injection — ASPECT-Enterprise 7.2 High2025-05-22
CVE-2025-30172 Admin Authorized Remote Code Execution — ASPECT-Enterprise 8.0 High2025-05-22
CVE-2024-9639 Authenticated Remote Code Execution — ASPECT-Enterprise 8.0 High2025-05-22
CVE-2025-46725 Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store — langroid 10.0AICriticalAI2025-05-20
CVE-2025-46724 Langroid has a Code Injection vulnerability in TableChatAgent — langroid 9.8 Critical2025-05-20
CVE-2025-26621 OpenCTI vulnerable to Denial of Service through web hook — opencti 7.6 High2025-05-19
CVE-2025-4866 weibocom rill-flow Management Console code injection — rill-flow 6.3 Medium2025-05-18
CVE-2025-47562 WordPress MapSVG plugin <= 8.5.34 - Content Injection Vulnerability — MapSVG 5.3 Medium2025-05-16
CVE-2025-48119 WordPress RS WP Book Showcase plugin <= 6.7.59 - Content Injection vulnerability — RS WP Book Showcase 5.3 Medium2025-05-16
CVE-2025-48120 WordPress MapSVG Lite plugin <= 8.6.9 - Arbitrary Shortcode Execution vulnerability — MapSVG 5.3 Medium2025-05-16
CVE-2025-4767 defog-ai introspect Test Endpoint integration_routes.py test_custom_tool code injection — introspect 5.3 Medium2025-05-16
CVE-2025-3053 UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.07 - Authenticated (Subscriber+) Remote Code Execution — UiPress lite | Effortless custom dashboards, admin themes and pages 8.8 High2025-05-15
CVE-2025-0134 Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM — Cortex XDR Broker VM 8.8AIHighAI2025-05-14
CVE-2025-4428 Remote Code Execution — Endpoint Manager Mobile 7.2 High2025-05-13
CVE-2025-43010 Code injection vulnerability in SAP S/4HANA Cloud Private Edition or On Premise(SCM Master Data Layer (MDL)) — SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) 8.3 High2025-05-13
CVE-2025-47271 OZI-Project/ozi-publish Code Injection vulnerability — publish 7.1AIHighAI2025-05-12
CVE-2025-4531 Seeyon Zhiyuan OA Web Application System Beetl Template EhrSalaryPayrollServiceImpl.class postData code injection — Zhiyuan OA Web Application System 6.3 Medium2025-05-11
CVE-2025-4208 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function — NEX-Forms – Ultimate Forms Plugin for WordPress 6.3 Medium2025-05-08
CVE-2024-13793 Wolmart | Multi-Vendor Marketplace WooCommerce Theme <= 1.8.11 - Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore — Wolmart | Multi-Vendor Marketplace WooCommerce Theme 7.3 High2025-05-08
CVE-2025-47691 WordPress Ultimate Member plugin <= 2.10.3 - Arbitrary Function Call vulnerability — Ultimate Member 5.5 Medium2025-05-07
CVE-2025-47481 WordPress GS Testimonial Slider plugin <= 3.2.9 - Content Injection vulnerability — GS Testimonial Slider 5.3 Medium2025-05-07
CVE-2025-2802 LayoutBoxx <= 0.3.1 - Unauthenticated Arbitrary Shortcode Execution — LayoutBoxx 7.3 High2025-05-06
CVE-2025-43845 GHSL-2025-015_Retrieval-based-Voice-Conversion-WebUI — Retrieval-based-Voice-Conversion-WebUI 9.8AICriticalAI2025-05-05
CVE-2025-24977 OpenCTI has remote code execution and sensitive secrets exposed through web hook — opencti 9.1 Critical2025-05-05
CVE-2025-4261 GAIR-NLP factool tool.py run_single code injection — factool 5.3 Medium2025-05-05

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.