Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-9581 Shortcodes AnyWhere <= 1.0.1 - Unauthenticated Arbitrary Shortcode Execution — Shortcodes AnyWhere 7.3 High2024-10-10
CVE-2024-43363 Remote code execution via Log Poisoning in Cacti — cacti 7.2 High2024-10-07
CVE-2024-8254 Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress 5.4 Medium2024-10-02
CVE-2024-9324 Intelbras InControl Relatório de Operadores Page operador code injection — InControl 6.3 Medium2024-09-29
CVE-2024-6983 Remote Code Execution in mudler/localai — mudler/localai 8.8AIHighAI2024-09-27
CVE-2024-8481 Special Text Boxes <= 6.2.4 - Unauthenticated Arbitrary Shortcode Execution — Special Text Boxes 7.3 High2024-09-25
CVE-2024-8623 MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution — MDTF – Meta Data and Taxonomies Filter 7.3 High2024-09-24
CVE-2024-0004 FlashArray 安全漏洞 — FlashArray 9.1 Critical2024-09-23
CVE-2024-9006 jeanmarc77 123solar config_invt1.php code injection — 123solar 6.3 Medium2024-09-19
CVE-2024-7104 Remote Code Execution in SFS Consulting's ww.Winsure — ww.Winsure 8.8 -2024-09-16
CVE-2024-8880 playSMS Template index.php code injection — playSMS 5.6 Medium2024-09-16
CVE-2024-8864 composiohq composio calculator.py Calculator code injection — composio 5.5 Medium2024-09-15
CVE-2024-8479 Simple Spoiler 1.2 - 1.3 - Unauthenticated Arbitrary Shortcode Execution — Simple Spoiler 7.3 High2024-09-14
CVE-2024-8271 FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution — FOX – Currency Switcher Professional for WooCommerce 7.3 High2024-09-14
CVE-2024-43469 Azure CycleCloud Remote Code Execution Vulnerability — Azure CycleCloud 8.2.0 8.8 High2024-09-10
CVE-2024-43393 Phoenix Contact: Configuration changes of the firewall services can lead to DoS in MGUARD devices — FL MGUARD 2102 8.1 High2024-09-10
CVE-2024-43392 Phoenix Contact: Firewall reconfiguration through the FW_environment variables in MGUARD devices — FL MGUARD 2102 8.1 High2024-09-10
CVE-2024-43391 Phoenix Contact: Firewall reconfiguration through the FW_PORTFORWARDING.SRC_IP in MGUARD devices — FL MGUARD 2102 8.1 High2024-09-10
CVE-2024-43390 Phoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devices — FL MGUARD 2102 8.1 High2024-09-10
CVE-2024-43389 Phoenix Contact: OSPF reconfiguration due to improper input validation in MGUARD devices — FL MGUARD 2102 8.1 High2024-09-10
CVE-2024-43388 Phoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devices — FL MGUARD 2102 8.8 High2024-09-10
CVE-2024-8258 Insecure Electron Fuses in Logitech Options Plus Allowing Arbitrary Code Execution on macOS — Logitech Options Plus 8.4AIHighAI2024-09-10
CVE-2024-6596 Endress+Hauser: Multiple products are vulnerable to code injection — Echo Curve Viewer 9.8 Critical2024-09-10
CVE-2024-8478 Affiliate Super Assistent <= 1.5.3 - Unauthenticated Arbitrary Shortcode Execution — Affiliate Super Assistent 7.3 High2024-09-10
CVE-2024-8268 Frontend Dashboard <= 2.2.4 - Authenticated (Subscriber+) Arbitrary Function Call — Frontend Dashboard 8.8 High2024-09-10
CVE-2024-8523 lmxcms SQL Command Execution Module admin.php formatData code injection — lmxcms 4.7 Medium2024-09-07
CVE-2024-7627 Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition — Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress 8.1 High2024-09-05
CVE-2024-45390 @blakeembrey/template vulnerable to code injection when attacker controls template input — js-template 7.3 High2024-09-03
CVE-2024-7345 Direct local client connections to MS Agents can bypass authentication — OpenEdge 8.3 High2024-09-03
CVE-2024-8374 Arbitrary Code Injection in Cura — Cura 7.8 High2024-09-03

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.