Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2020-25197 GE Reason RT43X Clocks Code Injection — Reason RT43X Clocks 9.8 Critical2022-03-18
CVE-2022-0811 cri-o 代码注入漏洞 — CRI-O 8.8 -2022-03-16
CVE-2021-25003 WPCargo < 6.9.0 - Unauthenticated RCE — WPCargo Track & Trace 9.8 -2022-03-14
CVE-2022-0921 Abusing Backup/Restore feature to achieve Remote Code Execution in microweber/microweber — microweber/microweber 7.2 -2022-03-11
CVE-2022-24734 Remote code execution in mybb — mybb 7.2 High2022-03-09
CVE-2022-24915 ICSA-22-062-01 IPCOMM ipDIO — IPCOMM ipDIO 8.0 High2022-03-09
CVE-2022-22985 ICSA-22-062-01 IPCOMM ipDIO — IPCOMM ipDIO 8.8 High2022-03-09
CVE-2022-0845 Code Injection in pytorchlightning/pytorch-lightning — pytorchlightning/pytorch-lightning 8.8 -2022-03-05
CVE-2022-22947 VMware Spring Cloud Gateway 代码注入漏洞 — Spring Cloud Gateway 10.0 -2022-03-03
CVE-2022-0819 Code Injection in dolibarr/dolibarr — dolibarr/dolibarr 8.1 -2022-03-02
CVE-2022-23642 Code Injection in Sourcegraph — sourcegraph 8.8 High2022-02-18
CVE-2022-24663 Remote Code Execution by Subscriber+ users via WordPress shortcode — PHP Everywhere 9.9 Critical2022-02-16
CVE-2022-24665 Remote Code Execution by by Contributor+ users via WordPress gutenberg block — PHP Everywhere 9.9 Critical2022-02-16
CVE-2022-24664 Remote Code Execution by by Contributor+ users via WordPress metabox — PHP Everywhere 9.9 Critical2022-02-16
CVE-2022-23434 Samsung Bixby Vision 代码注入漏洞 — Bixby Vision 4.4 Medium2022-02-11
CVE-2022-23426 Samsung DeX Home 代码注入漏洞 — Samsung Mobile Devices 4.4 Medium2022-02-11
CVE-2021-44521 Remote code execution for scripted UDFs — Apache Cassandra 9.1 -2022-02-11
CVE-2022-23631 Prototype Pollution leading to Remote Code Execution in superjson — superjson 9.1 Critical2022-02-09
CVE-2022-21686 Server Side Twig Template Injection in PrestaShop — PrestaShop 9.0 Critical2022-01-26
CVE-2022-23008 F5 Nginx 跨站脚本漏洞 — NGINX Controller API Management 7.1 -2022-01-25
CVE-2021-45029 Apache ShenYu 2.4.1 Groovy Code Injection & SpEL Injection — Apache ShenYu (incubating) 9.8 -2022-01-25
CVE-2021-23154 Command injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration provided — Lens 6.3 Medium2022-01-10
CVE-2022-22286 Samsung Bixby Routines App 代码注入漏洞 — Bixby Routines 4.4 Medium2022-01-07
CVE-2022-22285 Samsung Reminder App 代码注入漏洞 — Reminder 4.4 Medium2022-01-07
CVE-2022-22270 Samsung SMR 安全漏洞 — Samsung Mobile Devices 4.4 Medium2022-01-07
CVE-2021-23814 laravel-filemanager代码问题漏洞 — unisharp/laravel-filemanager 6.7 Medium2021-12-17
CVE-2021-43811 Code injection via unsafe YAML loading — sockeye 7.8 High2021-12-08
CVE-2021-44529 Ivanti Endpoint Manager 代码注入漏洞 — Ivanti EPM 9.8 -2021-12-08
CVE-2021-38448 Trane Symbio Improper Control of Generation of Code — Symbio 7.5 High2021-11-22
CVE-2021-22053 VMware Spring Cloud Netflix 代码注入漏洞 — Spring Cloud Netflix 8.8 -2021-11-19

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.