Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1490 Wago: Vulnerability in WBM through Open VPN — CC100 (0751-9x01) 7.2 High2026-04-09
CVE-2026-5848 jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection — JimuReport 4.7 Medium2026-04-09
CVE-2026-1516 Improper Control of Generation of Code ('Code Injection') in GitLab — GitLab 5.7 Medium2026-04-08
CVE-2026-39891 PraisonAI has a Template Injection in Agent Tool Definitions — PraisonAI 8.8 High2026-04-08
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration — vim 5.0 Medium2026-04-08
CVE-2026-34724 Zammad has a server-side template injection leading to RCE via AI Agent — zammad 7.2AIHighAI2026-04-08
CVE-2026-25776 Six Apart Movable Type 代码注入漏洞 — Movable Type 8.8AIHighAI2026-04-08
CVE-2026-5739 PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection — PowerJob 7.3 High2026-04-07
CVE-2026-39337 ChurchCRM Affected by Unauthenticated RCE in Install Wizard — CRM 10.0 Critical2026-04-07
CVE-2026-35197 Code injection in dye template expressions — dye 6.6 Medium2026-04-06
CVE-2026-35178 Workbench Affected by Remote Code Execution (RCE) via Malicious Cookie in Timezone Conversion — forceworkbench 7.2AIHighAI2026-04-06
CVE-2026-35171 Arbitrary Code Execution via Malicious Logging Configuration in Kedro — kedro 9.8 Critical2026-04-06
CVE-2026-26026 GLPI has a Server-Side Template Injection via Double-Compilation — glpi 9.1 Critical2026-04-06
CVE-2026-5631 assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection — gpt-researcher 7.3 High2026-04-06
CVE-2026-5594 premAI-io premsql followup.py eval code injection — premsql 6.3 Medium2026-04-05
CVE-2026-5584 Fosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injection — agenticSeek 7.3 High2026-04-05
CVE-2026-5562 provectus kafka-ui Endpoint testexecutions validateAccess code injection — kafka-ui 7.3 High2026-04-05
CVE-2026-5556 badlogic pi-mono loader.ts discoverAndLoadExtensions code injection — pi-mono 6.3 Medium2026-04-05
CVE-2026-3309 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 6.5 Medium2026-04-04
CVE-2026-34725 dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration — dbgate 8.3 High2026-04-02
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins — Red Hat Enterprise Linux 10 8.8 High2026-04-01
CVE-2026-29014 MetInfo CMS Unauthenticated PHP Code Injection RCE — MetInfo CMS 9.8 Critical2026-04-01
CVE-2026-35056 XenForo Remote Code Execution via Authenticated Admin — XenForo 7.2 High2026-04-01
CVE-2025-71281 XenForo Template Method Call Restriction Bypass — XenForo 8.8 High2026-04-01
CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names — lodash 8.1 High2026-03-31
CVE-2026-34060 Ruby LSP has arbitrary code execution through branch setting — ruby-lsp 8.8AIHighAI2026-03-31
CVE-2026-3300 Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field — Everest Forms Pro 9.8 Critical2026-03-31
CVE-2026-4257 Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality — Contact Form by Supsystic 9.8 Critical2026-03-30
CVE-2026-28505 Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist check — Tautulli 9.8 -2026-03-30
CVE-2026-5011 elecV2 elecV2P JSON webhook runJSFile code injection — elecV2P 6.3 Medium2026-03-28

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.