Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-23551 X-600M Code Injection — X-600M devices 9.1 Critical2023-02-13
CVE-2023-0788 Code Injection in thorsten/phpmyfaq — thorsten/phpmyfaq 8.1 High2023-02-12
CVE-2023-0792 Code Injection in thorsten/phpmyfaq — thorsten/phpmyfaq 6.5 Medium2023-02-12
CVE-2023-0671 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2023-02-04
CVE-2023-23477 IBM WebSphere Application Server code execution — WebSphere Application Server 8.1 High2023-02-03
CVE-2023-24576 Dell EMC NetWorker 代码注入漏洞 — NetWorker, NVE 7.5 High2023-02-03
CVE-2022-25967 Eta 安全漏洞 — eta 8.1 High2023-01-30
CVE-2023-23619 Improper Control of Generation of Code ('Code Injection') in @asyncapi/modelina — modelina 10.0 Critical2023-01-26
CVE-2022-25894 UFLO 代码注入漏洞 — com.bstek.uflo:uflo-core 9.8 Critical2023-01-25
CVE-2022-25860 simple-git 安全漏洞 — simple-git 8.1 High2023-01-24
CVE-2022-34456 Dell EMC Metro node 代码注入漏洞 — Metro node 8.8 High2023-01-18
CVE-2023-22731 Improper Control of Generation of Code in Twig rendered views in shopware — platform 10.0 Critical2023-01-17
CVE-2023-0297 Code Injection in pyload/pyload — pyload/pyload 8.3 -2023-01-14
CVE-2023-0022 Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP) — BusinessObjects Business Intelligence platform (Analysis edition for OLAP) 9.9 Critical2023-01-10
CVE-2023-0048 Code Injection in lirantal/daloradius — lirantal/daloradius 8.8 -2023-01-04
CVE-2015-10009 nterchange code_caller_controller.php getContent code injection — nterchange 5.5 Medium2023-01-02
CVE-2022-23474 editor.js contains Code Injection — editor.js 6.1 Medium2022-12-15
CVE-2022-23503 TYPO3 vulnerable to Arbitrary Code Execution via Form Framework — typo3 7.5 High2022-12-14
CVE-2022-41264 SAP Basis 代码注入漏洞 — BASIS 8.8 High2022-12-13
CVE-2022-4223 pgAdmin 代码注入漏洞 — pgadmin4 8.8 -2022-12-13
CVE-2022-46157 Remote php code execution in Akeneo PIM — pim-community-dev 8.8 High2022-12-09
CVE-2022-46166 Spring Boot Admins integrated notifier support allows arbitrary code execution — spring-boot-admin 8.1 High2022-12-09
CVE-2022-46742 PaddlePaddle 代码注入漏洞 — PaddlePaddle 10.0 Critical2022-12-07
CVE-2022-42699 WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Remote Code Execution (RCE) — Easy WP SMTP 9.1 Critical2022-12-06
CVE-2022-46333 Proofpoint Enterprise Protection perl eval() arbitrary command execution — enterprise_protection 7.2 High2022-12-06
CVE-2022-46161 Code injection in pdfmake — pdfmake 10.0 Critical2022-12-06
CVE-2022-23465 SwiftTerm vulnerable to arbitrary command execution — SwiftTerm 7.1 High2022-12-02
CVE-2022-3383 Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-Select — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 7.2 High2022-11-29
CVE-2022-3384 Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_options — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 7.2 High2022-11-29
CVE-2022-41945 Remote Code Execution (RCE) vulnerability in super-xray via URL input — super-xray 6.5 Medium2022-11-21

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.