Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13487 CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x 7.3 High2025-02-06
CVE-2025-25246 NETGEAR XR1000和NETGEAR XR500 安全漏洞 — XR1000 8.1 High2025-02-05
CVE-2025-24677 WordPress Post/Page Copying Tool to Export and Import post/page for Cross site Migration Plugin <= 2.0.3 - Remote Code Execution (RCE) vulnerability — Post/Page Copying Tool 9.9 Critical2025-02-04
CVE-2025-22204 Extension - regularlabs.com - Remote code execution vulnerability in the Sourcerer extensions < 12.0.0 for Joomla — Sourcerer for Joomla 9.8 -2025-02-04
CVE-2025-24959 Environment Variable Injection for dotenv API in zx — zx 9.8 -2025-02-03
CVE-2024-12415 AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode Execution — AI Infographic Maker 6.5 Medium2025-01-31
CVE-2024-13472 WooCommerce Product Table Lite <= 3.9.4 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting — Product Table and List Builder for WooCommerce Lite 7.3 High2025-01-31
CVE-2024-23921 ChargePoint Home Flex Command Injection — Home Flex 8.8 High2025-01-31
CVE-2024-23963 Alpine Halo9 Stack-based Buffer Overflow — Halo9 8.0 High2025-01-30
CVE-2024-11600 Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.0 - Authenticated (Administrator+) Remote Code Execution — Borderless – Addons and Templates for Elementor 7.2 High2025-01-30
CVE-2024-13453 Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Execution — Contact Form & SMTP Plugin for WordPress by PirateForms 7.3 High2025-01-30
CVE-2024-10001 Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling — Enterprise Server 8.3 -2025-01-29
CVE-2025-24482 FactoryTalk® View Site Edition - Local Code Injection — FactoryTalk® View Site Edition 7.8 -2025-01-28
CVE-2024-13499 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress 7.3 High2025-01-22
CVE-2024-13495 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress 7.3 High2025-01-22
CVE-2024-51941 Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts — Apache Ambari 8.8 -2025-01-21
CVE-2025-23209 Potential RCE with a compromised security key in craft/cms — cms 8.1 High2025-01-18
CVE-2024-10970 Motors – Car Dealer, Classifieds & Listing <= 1.4.43 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Custom Title — Motors – Car Dealership & Classified Listings Plugin 5.4 Medium2025-01-16
CVE-2025-23061 Mongoose 代码注入漏洞 — Mongoose 9.0 Critical2025-01-15
CVE-2024-49375 Remote Code Execution via Remote Model Loading in Rasa — rasa-pro-security-advisories 9.1 Critical2025-01-14
CVE-2025-21292 Windows Search Service Elevation of Privilege Vulnerability — Windows 10 Version 1809 8.8 High2025-01-14
CVE-2025-21187 Microsoft Power Automate Remote Code Execution Vulnerability — Power Automate for Desktop 7.8 High2025-01-14
CVE-2025-0060 Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence Platform 6.5 Medium2025-01-14
CVE-2024-9132 The administrator is able to configure an insecure captive portal script — Arista Edge Threat Management 8.1 High2025-01-10
CVE-2024-13187 Kingsoft WPS Office TCC code injection — WPS Office 5.3 Medium2025-01-08
CVE-2025-22136 Tabby has a TCC Bypass via Misconfigured Node Fuses — tabby 7.8 -2025-01-08
CVE-2024-11635 WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution — Iptanus File Upload 9.8 Critical2025-01-08
CVE-2024-11613 WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion — Iptanus File Upload 9.8 Critical2025-01-08
CVE-2024-56448 Huawei HarmonyOS 代码注入漏洞 — HarmonyOS 6.7 Medium2025-01-08
CVE-2025-22133 WeGIA Allows Arbitrary File Upload with Remote Code Execution (RCE) — WeGIA 10.0 Critical2025-01-07

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.