Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13738 Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution — Motors - Car Dealer, Rental & Listing WordPress theme 7.3 High2025-05-03
CVE-2025-4218 handrew browserpilot gpt_selenium_agent.py GPTSeleniumAgent code injection — browserpilot 5.3 Medium2025-05-02
CVE-2025-2421 Remote Code Execution in Profelis Informatics' SambaBox — SambaBox 9.8 Critical2025-05-02
CVE-2024-13420 Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Settings Updates — Benaa Framework 4.3 Medium2025-05-02
CVE-2025-4022 web-arena-x webarena evaluators.py HTMLContentEvaluator code injection — webarena 6.3 Medium2025-04-28
CVE-2024-32499 Newforma Project Center Server 安全漏洞 — Project Center Server 4.9 Medium2025-04-28
CVE-2023-42404 OneVision Workspace 安全漏洞 — Workspace 4.9 Medium2025-04-28
CVE-2025-3984 Apereo CAS Groovy Code RegisteredServiceSimpleFormController.java saveService code injection — CAS 5.0 Medium2025-04-27
CVE-2025-46579 ZTE GoldenDB Database product has a DDE injection vulnerability — GoldenDB 8.4 High2025-04-27
CVE-2024-13812 Anps Theme plugin <= 1.1.1 - Unauthenticated Arbitrary Shortcode Execution — Anps Theme plugin 6.5 Medium2025-04-26
CVE-2025-3491 Add custom page template <= 2.0.1 - Authenticated (Administrator+) PHP Code Injection to Remote Code Execution — Add custom page template 7.2 High2025-04-26
CVE-2024-13808 Xpro Elementor Addons - Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution — Xpro Elementor Addons - Pro 8.8 High2025-04-26
CVE-2025-2801 Create custom forms for WordPress with a smart form plugin for smart businesses <= 1.2.4 - Unauthenticated Arbitrary Shortcode Execution — Create custom forms for WordPress with a smart form plugin for smart businesses – Form builder for WordPress 7.3 High2025-04-26
CVE-2025-32432 Craft CMS Allows Remote Code Execution — cms 10.0 Critical2025-04-25
CVE-2025-3642 Moodle: authenticated remote code execution risk in the moodle lms equella repository 8.8 High2025-04-25
CVE-2025-3641 Moodle: authenticated remote code execution risk in the moodle lms dropbox repository 8.8 High2025-04-25
CVE-2025-3776 Verification SMS with TargetSMS <= 1.5 - Unauthenticated Limited Remote Code Execution — Verification SMS with TargetSMS 8.3 High2025-04-24
CVE-2025-1976 Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6 — Fabric OS 6.7 -2025-04-24
CVE-2025-0618 FireEye EDR 代码注入漏洞 — FireEye EDR HX 6.5 Medium2025-04-23
CVE-2025-23251 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.6 High2025-04-22
CVE-2025-3472 Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution — Ocean Extra 6.5 Medium2025-04-22
CVE-2025-3842 panhainan DS-Java FileUpload.java uploadUserPic.action code injection — DS-Java 6.3 Medium2025-04-21
CVE-2025-3509 Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation — Enterprise Server 6.6AIMediumAI2025-04-17
CVE-2025-32583 WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability — PDF 2 Post 9.9 Critical2025-04-17
CVE-2025-32596 WordPress Real Estate Manager plugin <= 7.3 - Arbitrary Code Execution vulnerability — Real Estate Manager 7.3 High2025-04-17
CVE-2025-26996 WordPress Sign-up Sheets plugin <= 2.3.0.1 - Shortcode Injection vulnerability — Sign-up Sheets 6.5 Medium2025-04-15
CVE-2025-3579 Code Injection Vulnerability in AiDex — AiDex 8.8AIHighAI2025-04-15
CVE-2025-3563 WuzhiCMS Setting index.php set code injection — WuzhiCMS 4.7 Medium2025-04-14
CVE-2025-3422 Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder 5.4 Medium2025-04-11
CVE-2025-32383 MaxKB has a reverse shell vulnerability in function library — MaxKB 4.3 Medium2025-04-10

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.