Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-28766 DLL injection in Zoom Windows Clients — Zoom Client for Meetings for Windows (32-bit) 3.3 Low2022-11-17
CVE-2022-40127 Apache Airflow <2.4.0 has an RCE in a bash example — Apache Airflow 8.8 -2022-11-14
CVE-2022-41882 Nextcloud Desktop vulnerable to code injection via malicious link — security-advisories 6.6 Medium2022-11-11
CVE-2022-41205 SAP GUI 代码注入漏洞 — SAP GUI for Windows 5.5 Medium2022-11-08
CVE-2022-3418 WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE — Import any XML or CSV File to WordPress 7.2 -2022-11-07
CVE-2022-3869 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2022-11-05
CVE-2022-3721 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2022-11-04
CVE-2022-43571 Remote Code Execution through dashboard PDF generation component in Splunk Enterprise — Splunk Enterprise 8.8 High2022-11-03
CVE-2022-39365 RCE vulnerability in Pimcore/Mail & Dynamic Text Layout — pimcore 9.8 Critical2022-10-27
CVE-2022-3394 WP All Export Pro < 1.7.9 - Authenticated Code Injection — WP All Export Pro 7.2 -2022-10-25
CVE-2022-39326 kartverket/github-workflows's run-terraform allows for RCE via terraform plan — github-workflows 8.8 High2022-10-25
CVE-2022-39327 Improper Control of Generation of Code ('Code Injection') in Azure CLI — azure-cli 8.1 High2022-10-25
CVE-2021-26727 spx_restservice SubNet_handler_func Multiple Command Injections and Stack-Based Buffer Overflows — IAC-AST2500A 10.0 Critical2022-10-24
CVE-2021-26728 spx_restservice KillDupUsr_func Command Injection and Stack-Based Buffer Overflow — IAC-AST2500A 10.0 Critical2022-10-24
CVE-2021-26729 spx_restservice Login_handler_func Command Injection and Multiple Stack-Based Buffer Overflows — IAC-AST2500A 10.0 Critical2022-10-24
CVE-2021-26731 spx_restservice modifyUserb_func Command Injection and Multiple Stack-Based Buffer Overflows — IAC-AST2500A 9.1 Critical2022-10-24
CVE-2022-35944 October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution) — october 6.2 Medium2022-10-13
CVE-2022-40628 Remote Code Execution Vulnerability in Tacitine Firewall — Firewall 9.8 Critical2022-09-23
CVE-2022-3245 Code Injection in display of tag title on saving tags in microweber/microweber — microweber/microweber 6.1 -2022-09-20
CVE-2022-3242 HTML code Injection in template search keyword in microweber/microweber — microweber/microweber 7.1 -2022-09-20
CVE-2022-36069 Poetry Argument Injection vulnerability can lead to local Code Execution — poetry 7.3 High2022-09-07
CVE-2022-36036 Improper Control of Generation of Code ('Code Injection') in mdx-mermaid — mdx-mermaid 3.6 Low2022-08-29
CVE-2022-25812 Transposh WordPress Translation < 1.0.8 - Admin+ RCE — Transposh WordPress Translation 7.2 -2022-08-22
CVE-2022-33721 SAMSUNG Mobile devices 安全漏洞 — Samsung Mobile Devices 4.4 Medium2022-08-05
CVE-2022-33725 SAMSUNG Mobile devices 安全漏洞 — Samsung Mobile Devices 4.0 Medium2022-08-05
CVE-2022-2636 Code Injection in hestiacp/hestiacp — hestiacp/hestiacp 8.5 High2022-08-05
CVE-2022-37396 JetBrains Rider 安全漏洞 — Rider 4.1 Medium2022-08-03
CVE-2022-37009 JetBrains IntelliJ IDEA 代码注入漏洞 — IntelliJ IDEA 3.9 Low2022-07-28
CVE-2022-35649 Moodle 输入验证错误漏洞 — Moodle 9.8 -2022-07-25
CVE-2022-34663 Siemens RUGGEDCOM 代码注入漏洞 — RUGGEDCOM i800 8.0 High2022-07-12

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.