Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21574 ComfyUI-Manager 安全漏洞 — ComfyUI-Manager 10.0 Critical2024-12-12
CVE-2024-10910 Grid Plus – Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category — Grid Plus – Unlimited grid layout 7.3 High2024-12-12
CVE-2024-54152 Angular Expressions - Remote Code Execution when using locals — angular-expressions 10.0 -2024-12-10
CVE-2024-10959 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth — Active Products Tables for WooCommerce. Use constructor to create tables 7.3 High2024-12-10
CVE-2024-21571 Snyk Code Agent 安全漏洞 — Code Agent 8.1 High2024-12-06
CVE-2024-51815 WordPress s2Member plugin <= 241114 - Remote Code Execution (RCE) vulnerability — s2Member 9.0 Critical2024-12-06
CVE-2024-10771 SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code execution — SICK InspectorP61x 8.8 High2024-12-06
CVE-2024-10681 ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.51 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup 6.3 Medium2024-12-06
CVE-2024-10909 Pojo Forms <= 1.4.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via form_preview_shortcode — Pojo Forms 6.3 Medium2024-12-06
CVE-2024-48840 Unauthorized Access — ASPECT-Enterprise 10.0 Critical2024-12-05
CVE-2024-48839 Remote Code Execution, RCE — ASPECT-Enterprise 10.0 Critical2024-12-05
CVE-2024-10952 Authors List <= 2.0.4 - Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax — Authors List 7.3 High2024-12-04
CVE-2024-11620 WordPress Rank Math SEO plugin <= 1.0.231 - Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) vulnerability — Rank Math SEO 9.8AICriticalAI2024-11-28
CVE-2024-8672 Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets 9.9 Critical2024-11-28
CVE-2024-52959 iota C.ai Conversational Platform - Improper Control of Generation of Code ('Code Injection') — iota C.ai Conversational Platform 7.3AIHighAI2024-11-27
CVE-2024-11002 InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template — InPost Gallery 6.3 Medium2024-11-26
CVE-2024-52899 IBM Data Virtualization Manager code execution — Data Virtualization Manager for z/OS 8.5 High2024-11-26
CVE-2024-53268 Lack of validation on openExternal allows 1 click remote code execution in joplin — joplin 7.3 High2024-11-25
CVE-2024-11034 Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form — Request a Quote for WooCommerce – Get a Quote Button 7.3 High2024-11-23
CVE-2021-38117 Possible Remote Code Execution Vulnerability OpenText iManager — iManager 8.8 High2024-11-22
CVE-2024-10094 Pegasystem PEGA Platform 安全漏洞 — Pega Infinity 9.1 Critical2024-11-20
CVE-2024-10899 WooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting — Product Table and List Builder for WooCommerce Lite 7.3 High2024-11-20
CVE-2024-11036 GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings — GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress 7.3 High2024-11-19
CVE-2024-11038 WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form — WPB Popup for Contact Form 7 – Showing Contact Form 7 Popup on Button Click 7.3 High2024-11-19
CVE-2024-48962 Apache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE) — Apache OFBiz 8.8AIHighAI2024-11-18
CVE-2024-10262 Drop Shadow Boxes <= 1.7.14 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Drop Shadow Boxes 6.3 Medium2024-11-16
CVE-2024-9839 Uix Slideshow <= 1.6.5 - Unauthenticated Arbitrary Shortcode Execution — Uix Slideshow 7.3 High2024-11-16
CVE-2024-49362 Remote Code Execution on click of <a> Link in markdown preview — joplin 7.7 High2024-11-14
CVE-2024-5082 Nexus Repository 2 - Remote Code Execution — Nexus Repository 7.2 -2024-11-14
CVE-2024-21541 npm dom-iterator 安全漏洞 — dom-iterator 7.3 High2024-11-13

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.