Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-54997 OpenBao: Privileged Operator May Execute Code on the Underlying Host — openbao 9.1 Critical2025-08-09
CVE-2025-54417 Craft contains a theoretical bypass for CVE-2025-23209 — cms 6.6 -2025-08-09
CVE-2025-54940 WordPress plugin Advanced Custom Fields 代码注入漏洞 — Advanced Custom Fields 6.1 -2025-08-08
CVE-2025-8518 givanz Vvveb Code Editor code.php save code injection — Vvveb 4.7 Medium2025-08-04
CVE-2025-6204 Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 — DELMIA Apriso 8.0 High2025-08-04
CVE-2025-54593 FreshRSS is vulnerable to RCE attacks by authenticated admin — FreshRSS 7.2 High2025-08-01
CVE-2025-6000 Arbitrary Remote Code Execution via Plugin Catalog Abuse — Vault 9.1 Critical2025-08-01
CVE-2013-10035 ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution — ProcessMaker Open Source 8.8AIHighAI2025-07-31
CVE-2025-7361 Code Injection Vulnerability in NI LabVIEW when using CIN nodes — LabVIEW 7.8 High2025-07-29
CVE-2025-4056 Glib: glib crash after long command line 7.5 High2025-07-28
CVE-2025-5120 Sandbox Escape Vulnerability in huggingface/smolagents — huggingface/smolagents 10.0 -2025-07-27
CVE-2025-54451 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23
CVE-2025-42947 Code Injection vulnerability in SAP FICA ODN framework — SAP FICA ODN framework 5.5 Medium2025-07-23
CVE-2025-6213 Nginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code Execution — Nginx Cache Purge Preload 7.2 High2025-07-22
CVE-2025-0664 Trellix Endpoint Security 代码注入漏洞 — Trellix Endpoint Security (HX) Agent 7.3 -2025-07-21
CVE-2025-54068 Livewire vulnerable to remote command execution during property update hydration — livewire 9.8AICriticalAI2025-07-17
CVE-2025-53928 MaxKB has RCE in MCP call — MaxKB 4.6 Medium2025-07-17
CVE-2025-53927 MaxKB sandbox bypass — MaxKB 4.6 Medium2025-07-17
CVE-2025-5396 Bears Backup <= 2.0.0 - Unauthenticated Remote Code Execution — Bears Backup 9.8 Critical2025-07-17
CVE-2025-53890 pyLoad vulnerable to remote code execution through js2py onCaptchaResult — pyload 9.8 Critical2025-07-14
CVE-2024-58258 SugarCRM 代码注入漏洞 — SugarCRM 7.2 High2025-07-13
CVE-2025-50123 Schneider Electric EcoStruxure IT Data Center Expert 代码注入漏洞 — EcoStruxure™ IT Data Center Expert 7.2AIHighAI2025-07-11
CVE-2025-5392 GB Forms DB <= 1.0.2 - Unauthenticated Remote Code Execution — GB Forms DB 9.8 Critical2025-07-11
CVE-2025-53626 pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation — pdfme 6.1 Medium2025-07-10
CVE-2024-7650 Remote code execution vulnerability discovered in OpenText™ Directory Services CE 23.4 — Directory Services 9.8AICriticalAI2025-07-10
CVE-2025-53547 Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution — helm 8.5 High2025-07-08
CVE-2025-47988 Azure Monitor Agent Remote Code Execution Vulnerability — Azure Monitor 7.5 High2025-07-08
CVE-2025-49704 Microsoft SharePoint Remote Code Execution Vulnerability — Microsoft SharePoint Enterprise Server 2016 8.8 High2025-07-08
CVE-2025-6744 Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution — Woodmart 7.3 High2025-07-08
CVE-2025-42967 Code Injection vulnerability in SAP S/4HANA and SAP SCM (Characteristic Propagation) — SAP S/4HANA and SAP SCM (Characteristic Propagation) 9.9 Critical2025-07-08

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.