Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1296

1296 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6016 H2O Remote Code Execution via POJO Model Import — h2oai/h2o-3 8.8 -2023-11-16
CVE-2023-48217 Remote code execution via form uploads in statamic/cms — cms 8.8 High2023-11-14
CVE-2023-36437 Azure DevOps Server Remote Code Execution Vulnerability — Azure Pipelines Agent 8.8 High2023-11-14
CVE-2023-6131 Code Injection in salesagility/suitecrm — salesagility/suitecrm 2.7 -2023-11-14
CVE-2023-6126 Code Injection in salesagility/suitecrm — salesagility/suitecrm 2.7 -2023-11-14
CVE-2023-6125 Code Injection in salesagility/suitecrm — salesagility/suitecrm 2.7 -2023-11-14
CVE-2023-5550 Moodle: rce due to lfi risk in some misconfigured shared hosting environments 6.5 Medium2023-11-09
CVE-2023-5540 Moodle: authenticated remote code execution risk in imscp 4.7 Medium2023-11-09
CVE-2023-5539 Moodle: authenticated remote code execution risk in lesson 4.7 Medium2023-11-09
CVE-2023-45849 Arbitrary Code Execution in Helix Core — Helix Core 9.0 Critical2023-11-08
CVE-2023-46243 Code execution via the edit action in XWiki platform — xwiki-platform 10.0 Critical2023-11-07
CVE-2023-46242 Code injection in XWiki Platform — xwiki-platform 9.7 Critical2023-11-07
CVE-2023-46731 Remote code execution through the section parameter in Administration as guest in XWiki Platform — xwiki-platform 10.0 Critical2023-11-06
CVE-2023-20063 Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability — Cisco Firepower Management Center 8.2 High2023-11-01
CVE-2023-42658 InSpec Archive Command Vulnerable to Maliciously Crafted Profile — Chef InSpec 8.8 High2023-10-31
CVE-2023-40050 Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application — Chef Automate 9.9 Critical2023-10-31
CVE-2023-43792 baserCMS Code Injection Vulnerability in Mail Form Feature — basercms 9.8 -2023-10-30
CVE-2023-5843 Ads by datafeedr.com <= 1.1.3 - Unauthenticated (Limited) Remote Code Execution — Ads by datafeedr.com 9.0 Critical2023-10-30
CVE-2023-28796 IPC Bypass Through PLT Section in ELF — Client Connector 7.1 High2023-10-23
CVE-2023-28793 Heap Based Buffer Overflow in Library — Client Connector 7.8 High2023-10-23
CVE-2023-29453 Agent 2 package are built with Go version affected by CVE-2023-24538 — Zabbix 9.8 Critical2023-10-12
CVE-2023-43661 Cachet vulnerable to Authenticated Remote Code Execution — cachet 8.8 -2023-10-11
CVE-2023-36789 Skype for Business Remote Code Execution Vulnerability — Skype for Business Server 2019 CU7 7.2 High2023-10-10
CVE-2023-43625 Siemens Simcenter Amesim 代码注入漏洞 — Simcenter Amesim 9.8 Critical2023-10-10
CVE-2023-44392 Arbitrary code execution vulnerability when using shared Kubernetes cluster — garden 8.3 High2023-10-09
CVE-2023-35897 IBM Spectrum Protect code execution — Storage Protect Client 8.4 High2023-10-06
CVE-2023-5201 OpenHook <= 4.3.0 - Authenticated (Subscriber+) Remote Code Execution via Shortcode — OpenHook 9.9 Critical2023-09-30
CVE-2023-43651 Remote code execution on the host system via MongoDB shell in jumpserver — jumpserver 8.6 High2023-09-27
CVE-2023-5221 ForU CMS index.php code injection — CMS 4.7 Medium2023-09-27
CVE-2023-0626 Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route — Docker Desktop 8.0 High2023-09-25

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1296 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.