Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-31414 Elastic Kibana 代码注入漏洞 — Kibana 9.1 -2023-05-04
CVE-2022-36963 SolarWinds Platform Deserialization of Untrusted Data Vulnerability — SolarWinds Platform 7.2 High2023-04-21
CVE-2023-25550 Schneider Electric StruxureWare Data Center Expert 代码注入漏洞 — StruxureWare Data Center Expert 7.2 High2023-04-18
CVE-2023-25549 Schneider Electric StruxureWare Data Center Expert 代码注入漏洞 — StruxureWare Data Center Expert 7.2 High2023-04-18
CVE-2023-2056 DedeCMS module_main.php GetSystemFile code injection — DedeCMS 6.3 Medium2023-04-14
CVE-2023-27897 Code Injection vulnerability in SAP CRM — CRM 6.0 Medium2023-04-11
CVE-2023-1947 taoCMS admin.php code injection — taoCMS 6.3 Medium2023-04-07
CVE-2023-28706 Apache Airflow Hive Provider Beeline Remote Command Execution — Apache Airflow Hive Provider 9.8 -2023-04-07
CVE-2023-26119 HtmlUnit 安全漏洞 — net.sourceforge.htmlunit:htmlunit 9.8 Critical2023-04-03
CVE-2023-1773 Rockoa Configuration File webmainConfig.php code injection — Rockoa 6.3 Medium2023-03-31
CVE-2023-24835 Softnext SPAM SQR - Code Injection — SPAM SQR 7.2 High2023-03-27
CVE-2022-38745 Apache OpenOffice: Empty entry in Java class path — Apache OpenOffice 9.8 -2023-03-24
CVE-2023-28333 Moodle: pix helper potential mustache code injection risk 9.8 -2023-03-23
CVE-2023-1306 Rapid7 InsightCloudSec resource.db() method access — InsightCloudSec 8.8 -2023-03-21
CVE-2023-1304 Rapid7 InsightCloudSec getattr() method access — InsightCloudSec 8.8 -2023-03-21
CVE-2023-1482 HkCms External Plugin code injection — HkCms 4.7 Medium2023-03-18
CVE-2023-0598 GE Digital Proficy Code Injection — Proficy iFIX 7.8 High2023-03-16
CVE-2023-27893 Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI) — Solution Manager and ABAP managed systems 8.8 High2023-03-14
CVE-2023-1367 Code Injection in alextselegidis/easyappointments — alextselegidis/easyappointments 3.8 -2023-03-13
CVE-2023-1283 Code Injection in builderio/qwik — builderio/qwik 10.0 Critical2023-03-08
CVE-2023-26107 SketchSVG 代码注入漏洞 — sketchsvg 6.9 Medium2023-03-06
CVE-2023-22381 Code injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub Actions — Enterprise Server 4.1 Medium2023-03-02
CVE-2023-1097 Unauthenticated Command Injection EG7035-M11 Series — EG7035-M11 9.3 Critical2023-03-01
CVE-2023-1005 JP1016 Markdown-Electron code injection — Markdown-Electron 5.3 Medium2023-02-24
CVE-2023-1004 MarkText WSH JScript code injection — MarkText 5.3 Medium2023-02-24
CVE-2023-1003 Typora WSH JScript code injection — Typora 5.3 Medium2023-02-24
CVE-2023-25657 Remote code execution in Jinja2 template rendering in Nautobot — nautobot 7.5 High2023-02-21
CVE-2021-26277 Security Advisory | PendingIntent hijacking vulnerability in Framework Services — Frame service 5.6 Medium2023-02-17
CVE-2023-0877 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2023-02-17
CVE-2023-21553 Azure DevOps Server Remote Code Execution Vulnerability — Azure DevOps Server 2020.1.2 7.5 High2023-02-14

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.