Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-49048 TorchGeo Remote Code Execution Vulnerability — Microsoft TorchGeo 8.1 High2024-11-12
CVE-2024-10958 WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay — WP Photo Album Plus 7.3 High2024-11-10
CVE-2024-10261 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction 7.3 High2024-11-09
CVE-2024-10640 The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution — FOX – Currency Switcher Professional for WooCommerce 7.3 High2024-11-09
CVE-2024-51757 Fixes security vulnerability that allowed for server side code to be executed by a <script> tag — happy-dom 6.1AIMediumAI2024-11-06
CVE-2024-10263 Tickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution — Tickera – Sell Tickets & Manage Events 7.3 High2024-11-05
CVE-2024-10035 Code Injection in BG-TEK's CoslatV3 — CoslatV3 7.2AIHighAI2024-11-04
CVE-2024-21537 Lilconfig 安全漏洞 — lilconfig 8.8 High2024-10-31
CVE-2024-9846 Enable Shortcodes inside Widgets,Comments and Experts <= 1.0.0 - Unauthenticated Arbitrary Shortcode Execution — Enable Shortcodes inside Widgets,Comments and Experts 7.3 High2024-10-30
CVE-2024-10505 wuzhicms block.php edit code injection — wuzhicms 6.3 Medium2024-10-30
CVE-2024-8923 Sandbox Escape in Now Platform — Now Platform 9.8 Critical2024-10-29
CVE-2024-50450 WordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Bypass Vulnerability vulnerability — MDTF 7.3 High2024-10-28
CVE-2024-50492 WordPress ScottCart plugin <= 1.1 - Remote Code Execution (RCE) vulnerability — ScottCart 8.3 High2024-10-28
CVE-2024-50498 WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability — WP Query Console 10.0 Critical2024-10-28
CVE-2024-9162 All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection — All-in-One WP Migration and Backup 7.2 High2024-10-28
CVE-2024-9772 Uix Shortcodes – Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution — Uix Shortcodes 7.3 High2024-10-26
CVE-2024-47158 NEUMANN N-LINE 安全漏洞 — N-LINE 9.6 -2024-10-25
CVE-2024-20485 Cisco Firepower Threat Defense和Cisco Adaptive Security Appliance 安全漏洞 — Cisco Adaptive Security Appliance (ASA) Software 6.0 Medium2024-10-23
CVE-2024-9050 Networkmanager-libreswan: local privilege escalation via leftupdown 7.8 High2024-10-22
CVE-2024-10131 Remote Code Execution in infiniflow/ragflow — infiniflow/ragflow 9.8 -2024-10-19
CVE-2024-9593 Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution — Time Clock Pro 8.3 High2024-10-18
CVE-2024-9264 Grafana SQL Expressions allow for remote code execution — Grafana 9.9 Critical2024-10-18
CVE-2024-10073 flairNLP flair Mode File Loader clustering.py ClusteringModel code injection — flair 5.0 Medium2024-10-17
CVE-2024-45766 Dell OpenManage Enterprise 代码注入漏洞 — Dell OpenManage Enterprise 8.0 High2024-10-17
CVE-2024-49254 WordPress ajax-extend plugin <= 1.0 - Remote Code Execution (RCE) vulnerability — ajax-extend 10.0 Critical2024-10-16
CVE-2024-9061 WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add — WP Popup Builder – Popup Forms and Marketing Lead Generation 7.3 High2024-10-16
CVE-2024-45271 MB connect line/Helmholz: Remote code execution due to improper input validation — mbNET.mini 8.4 High2024-10-15
CVE-2024-9837 AADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution — AADMY – Add Auto Date Month Year Into Posts 7.3 High2024-10-15
CVE-2024-8760 Stackable – Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection — Stackable – Page Builder Gutenberg Blocks 5.3 Medium2024-10-12
CVE-2024-21534 JSONPath Plus 安全漏洞 — jsonpath-plus 9.8 Critical2024-10-11

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.