Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1296

1296 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-39877 Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler — Apache Airflow 8.8AIHighAI2024-07-17
CVE-2024-39700 Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action — extension-template 10.0 Critical2024-07-16
CVE-2024-6655 Gtk3: gtk2: library injection from cwd 7.0 High2024-07-16
CVE-2024-39915 Authenticated remote code execution in Thruk — Thruk 10.0 Critical2024-07-15
CVE-2024-21513 LangChain 安全漏洞 — langchain-experimental 8.5 High2024-07-15
CVE-2024-6345 Remote Code Execution in pypa/setuptools — pypa/setuptools 9.8 -2024-07-15
CVE-2024-21832 PingFederate REST API Data Store Injection — PingFederate 3.5 Low2024-07-09
CVE-2024-37934 WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability — Ninja Forms 5.4 Medium2024-07-09
CVE-2024-6365 Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution — Product Table for WooCommerce by WBW 9.8 Critical2024-07-09
CVE-2024-38346 Apache CloudStack: Unauthenticated cluster service port leads to remote execution — Apache CloudStack 10.0 -2024-07-05
CVE-2024-3995 Command Injection in Helix ALM — Helix ALM 6.7AIMediumAI2024-06-28
CVE-2024-5751 Remote Code Execution in BerriAI/litellm — berriai/litellm 9.8AICriticalAI2024-06-27
CVE-2024-5826 Remote Code Execution via Prompt Injection in vanna-ai/vanna — vanna-ai/vanna 9.8AICriticalAI2024-06-27
CVE-2024-5979 Denial of Service via Invalid Argument in h2oai/h2o-3 — h2oai/h2o-3 7.5AIHighAI2024-06-27
CVE-2024-37109 WordPress WishList Member X plugin < 3.26.7 - Authenticated Arbitrary PHP Code Execution vulnerability — WishList Member X 9.9 Critical2024-06-24
CVE-2024-5683 Remote Code Execution in Next4Biz's BPM — Business Process Manangement (BPM) 9.8 Critical2024-06-24
CVE-2024-3121 Remote Code Execution in create_conda_env function in parisneo/lollms — parisneo/lollms 9.8 -2024-06-24
CVE-2024-38319 IBM Security SOAR code execution — Security SOAR 7.5 High2024-06-22
CVE-2023-45673 Arbitrary code execution on click of PDF links in Joplin — joplin 8.9 High2024-06-21
CVE-2024-37899 Disabling a user account changes its author, allowing RCE from user account in XWiki — xwiki-platform 9.1 Critical2024-06-20
CVE-2024-32030 Remote code execution via JNDI resolution in JMX metrics collection in Kafka UI — kafka-ui 8.1 High2024-06-19
CVE-2024-3105 Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution — Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts 9.9 Critical2024-06-15
CVE-2024-37885 Code injection in Nextcloud Desktop Client for macOS — security-advisories 3.8 Low2024-06-14
CVE-2024-1577 Remote Code Execution in MegaBIP — MegaBIP 9.8AICriticalAI2024-06-12
CVE-2024-34761 Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Arbitrary Function Execution vulnerability — Advanced Custom Fields PRO 8.5 High2024-06-10
CVE-2024-4889 Code Injection in berriai/litellm — berriai/litellm 7.8AIHighAI2024-06-06
CVE-2024-4194 Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution — Album and Image Gallery Plus Lightbox 6.5 Medium2024-06-06
CVE-2024-25600 WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability — Bricks Builder 10.0 Critical2024-06-04
CVE-2024-37061 MLflow 安全漏洞 — MLflow 8.8 High2024-06-04
CVE-2024-36120 javascript-deobfuscator crafted payload can lead to code execution — javascript-deobfuscator 8.2 High2024-05-31

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1296 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.