Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-56278 WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability — WP Ultimate Exporter 9.1 Critical2025-01-07
CVE-2024-12471 Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload — Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator 8.8 High2025-01-07
CVE-2024-12252 SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution) — SEO LAT Auto Post 9.8 Critical2025-01-07
CVE-2024-12419 Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting — WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms 6.5 Medium2025-01-07
CVE-2024-11733 WordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode Execution — WP Popular Posts 7.3 High2025-01-03
CVE-2024-56803 Ghostty improperly handles window title sequences which can lead to arbitrary command execution — ghostty 6.6 -2024-12-31
CVE-2024-12238 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Ninja Forms – The Contact Form Builder That Grows With You 6.3 Medium2024-12-29
CVE-2024-12908 Delinea Secret Server 安全漏洞 — Secret Server 6.9 Medium2024-12-26
CVE-2024-12952 melMass comfy_mtb Dependency endpoint.py run_command code injection — comfy_mtb 6.3 Medium2024-12-26
CVE-2024-12652 Intumit SmartRobot′s Conversational AI Platform - Improper Control of Generation of Code ('Code Injection') — SmartRobot′s Conversational AI Platform 8.8 -2024-12-26
CVE-2024-12900 FoxCMS Configuration File installdb.php code injection — FoxCMS 6.3 Medium2024-12-23
CVE-2024-11977 kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution — kk Star Ratings – Rate Post & Collect User Feedbacks 7.3 High2024-12-21
CVE-2024-56334 Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation — systeminformation 7.8 High2024-12-20
CVE-2024-56333 Remote code execution in onyxia-api — onyxia 9.9 -2024-12-20
CVE-2024-56327 Malicious plugin names, recipients, or identities can cause arbitrary binary execution in pyrage — pyrage 7.5 -2024-12-19
CVE-2024-12729 Sophos Firewall 安全漏洞 — Sophos Firewall 8.8 High2024-12-19
CVE-2024-12789 PbootCMS IndexController.php code injection — PbootCMS 6.3 Medium2024-12-19
CVE-2024-9154 Authenticated Remote Code Execution — Ewon Flexy 205 9.8 -2024-12-19
CVE-2024-11740 Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution — Download Manager 7.3 High2024-12-19
CVE-2024-56145 RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms — cms 9.8 -2024-12-18
CVE-2024-56051 WordPress WPLMS plugin < 1.9.9.5 - Student+ Remote Code Execution (RCE) vulnerability — WPLMS 8.5 High2024-12-18
CVE-2024-21546 laravel-filemanager 安全漏洞 — unisharp/laravel-filemanager 9.8 Critical2024-12-18
CVE-2024-55661 Laravel Pulse Allows Remote Code Execution via Unprotected Query Method — pulse 8.8 -2024-12-13
CVE-2024-21577 ComfyUI_AceNodes 安全漏洞 — ComfyUI-Ace-Nodes 10.0 Critical2024-12-13
CVE-2024-21576 ComfyUI Bmad Nodes 安全漏洞 — ComfyUI-Bmad-Nodes 10.0 Critical2024-12-13
CVE-2024-11012 Notibar – Notification Bar for WordPress <= 2.1.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via njt_nofi_text — Notibar – Notification Bar for WordPress 6.3 Medium2024-12-13
CVE-2024-12417 Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode Execution — Simple Link Directory 6.5 Medium2024-12-13
CVE-2024-12421 Coupon Affiliates – Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting — Coupon Affiliates – Affiliate Plugin for WooCommerce 6.5 Medium2024-12-13
CVE-2024-12420 WPMobile.App — Android and iOS Mobile Application <= 11.52 - Unauthenticated Arbitrary Shortcode Execution — WPMobile.App 6.5 Medium2024-12-13
CVE-2024-12333 WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution — Woodmart 6.5 Medium2024-12-12

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.