Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-59041 Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email — claude-code 8.8AIHighAI2025-09-10
CVE-2025-58764 Claude Code rg command had Command Injection that allowed bypass of user approval prompt for command execution — claude-code 8.8AIHighAI2025-09-10
CVE-2025-59042 PyInstaller has local privilege escalation vulnerability — pyinstaller 7.5AIHighAI2025-09-09
CVE-2025-58768 DeepChat's Mermaid rendering has XSS leading to RCE — deepchat 9.7 Critical2025-09-09
CVE-2025-9539 AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation — AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress 8.0 High2025-09-09
CVE-2025-9489 WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names — WP-Members Membership Plugin 5.0 Medium2025-09-09
CVE-2025-42922 Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service) — SAP NetWeaver AS Java (Deploy Web Service) 9.9 Critical2025-09-09
CVE-2025-58745 WeGIA has a bypass for the fix for CVE-2025-22133 - Arbitrary File Upload leads to Remote Code Execution (RCE) — WeGIA 10.0 Critical2025-09-08
CVE-2025-10097 SimStudioAI sim route.ts code injection — sim 6.3 Medium2025-09-08
CVE-2025-7366 Rehub <= 19.9.7 - Unauthenticated Arbitrary Shortcode Execution via re_filterpost — REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme 7.3 High2025-09-06
CVE-2025-58827 WordPress Job Board Manager Plugin <= 2.1.61 - Content Injection Vulnerability — Job Board Manager 3.8 Low2025-09-05
CVE-2025-55305 Electron is vulnerable to Code Injection via resource modification — electron 6.1 Medium2025-09-04
CVE-2025-9517 atec Debug <= 1.2.22 - Authenticated (Administrator+) Remote Code Execution — atec Debug 7.2 High2025-09-04
CVE-2025-9519 Easy Timer <= 4.2.1 - Authenticated (Editor+) Remote Code Execution via Shortcode — Easy Timer 7.2 High2025-09-04
CVE-2025-9959 Sandbox escape in smolagents Local Python execution environment via dunder attributes 7.6 High2025-09-03
CVE-2025-58176 Dive's improper processing of custom urls can lead to Remote Code Execution — Dive 8.8 High2025-09-03
CVE-2024-48908 lychee-action vulnerable to arbitrary code injection in composite action — lychee-action 8.4AIHighAI2025-08-28
CVE-2025-54731 WordPress YouTube Showcase Plugin <= 3.5.1 - PHP Object Injection Vulnerability — YouTube Showcase 8.1 High2025-08-28
CVE-2025-48100 WordPress bidorbuy Store Integrator plugin <= 2.12.0 - Remote Code Execution (RCE) vulnerability — bidorbuy Store Integrator 9.1 Critical2025-08-28
CVE-2025-5101 Improper Control of Generation of Code ('Code Injection') in GitLab — GitLab 5.0 Medium2025-08-27
CVE-2025-34159 Coolify Docker Compose Directive Injection in Application Deployment Workflow — Coolify 8.8AIHighAI2025-08-27
CVE-2025-30057 Authenticated RCE with uhcapache privileges in ConvertToPDF — CGM CLININET 9.8AICriticalAI2025-08-27
CVE-2025-30056 Calling system commands via RunCommand — CGM CLININET 9.8AICriticalAI2025-08-27
CVE-2025-30055 Conditional RCE via the "system" function — CGM CLININET 9.8AICriticalAI2025-08-27
CVE-2025-2313 RCE via Print.pl in uhcPrintServerPrint — CGM CLININET 9.8AICriticalAI2025-08-27
CVE-2025-23315 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2025-08-26
CVE-2025-23314 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2025-08-26
CVE-2025-23313 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2025-08-26
CVE-2025-23312 NVIDIA NeMo Framework 注入漏洞 — NeMo Framework 7.8 High2025-08-26
CVE-2025-23307 NVIDIA NeMo Curator 代码注入漏洞 — NVIDIA NeMo Curator 7.8 High2025-08-26

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.