Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-67489 @vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server — vite-plugin-react 9.8 Critical2025-12-09
CVE-2025-66457 Elysia affected by arbitrary code injection through cookie config — elysia 8.8AIHighAI2025-12-09
CVE-2025-13642 ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 5.4 Medium2025-12-09
CVE-2025-66533 WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability — GiveWP 6.5 Medium2025-12-09
CVE-2025-42880 Code Injection vulnerability in SAP Solution Manager — SAP Solution Manager 9.9 Critical2025-12-09
CVE-2025-66222 DeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE) — deepchat 9.7 Critical2025-12-03
CVE-2024-32641 Masa CMS Vulnerable to Pre-Auth RCE via JSON API — MasaCMS 9.8 Critical2025-12-03
CVE-2025-13486 Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form — Advanced Custom Fields: Extended 9.8 Critical2025-12-03
CVE-2025-13658 Industrial Video & Control Longwatch has a Code Injection vulnerability — Longwatch 9.8AICriticalAI2025-12-02
CVE-2025-66448 vLLM vulnerable to remote code execution via transformers_utils/get_config — vllm 7.1 High2025-12-01
CVE-2025-66299 Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS — grav 8.8 High2025-12-01
CVE-2025-66294 Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass — grav 7.2AIHighAI2025-12-01
CVE-2025-13792 Qualitor getResumo.php eval code injection — Qualitor 7.3 High2025-11-30
CVE-2025-13786 taosir WTCMS index.php fetch code injection — WTCMS 7.3 High2025-11-30
CVE-2025-66224 OrangeHRM is Vulnerable to Code Execution Through Arbitrary File Write from Sendmail Parameter Injection — orangehrm 8.1 -2025-11-29
CVE-2025-59302 Apache CloudStack: Potential remote code execution on Javascript engine defined rules — Apache CloudStack 7.2 -2025-11-27
CVE-2025-62593 Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack — ray 9.6AICriticalAI2025-11-26
CVE-2025-33204 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2025-11-25
CVE-2025-6389 Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback — Sneeit Framework 9.8 Critical2025-11-25
CVE-2025-65108 md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter — md-to-pdf 10.0 Critical2025-11-21
CVE-2025-65099 Claude Code vulnerable to command execution prior to startup trust dialog — claude-code 8.8AIHighAI2025-11-19
CVE-2025-65026 esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript — esm.sh 6.1 Medium2025-11-19
CVE-2025-10703 Progress多款产品 代码注入漏洞 — DataDirect Connect for JDBC for Amazon Redshift 9.8AICriticalAI2025-11-19
CVE-2025-10702 Progress多款产品 代码注入漏洞 — DataDirect Connect for JDBC for Amazon Redshift 9.8AICriticalAI2025-11-19
CVE-2025-13035 Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains — Code Snippets 8.0 High2025-11-19
CVE-2025-33184 NVIDIA Isaac-GR00T 代码注入漏洞 — NVIDIA Isaac-GR00T N1.5 7.8 High2025-11-18
CVE-2025-33183 NVIDIA Isaac-GR00T 代码注入漏洞 — NVIDIA Isaac-GR00T N1.5 7.8 High2025-11-18
CVE-2025-7711 Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description — Classified Listing – AI-Powered Classified ads & Business Directory Plugin 5.4 Medium2025-11-17
CVE-2025-12733 Import any XML, CSV or Excel File to WordPress (WP All Import) <= 3.9.6 - Authenticated (Administrator+) Remote Code Execution via Conditional Logic — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets 8.8 High2025-11-13
CVE-2024-48829 Dell SmartFabric OS10 Software 代码注入漏洞 — SmartFabric OS10 Software 6.7 Medium2025-11-12

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.