Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1298

1298 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-26277 Security Advisory | PendingIntent hijacking vulnerability in Framework Services — Frame service 5.6 Medium2023-02-17
CVE-2023-0877 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2023-02-17
CVE-2023-21553 Azure DevOps Server Remote Code Execution Vulnerability — Azure DevOps Server 2020.1.2 7.5 High2023-02-14
CVE-2023-23551 X-600M Code Injection — X-600M devices 9.1 Critical2023-02-13
CVE-2023-0788 Code Injection in thorsten/phpmyfaq — thorsten/phpmyfaq 8.1 High2023-02-12
CVE-2023-0792 Code Injection in thorsten/phpmyfaq — thorsten/phpmyfaq 6.5 Medium2023-02-12
CVE-2023-0671 Code Injection in froxlor/froxlor — froxlor/froxlor 4.6 -2023-02-04
CVE-2023-23477 IBM WebSphere Application Server code execution — WebSphere Application Server 8.1 High2023-02-03
CVE-2023-24576 Dell EMC NetWorker 代码注入漏洞 — NetWorker, NVE 7.5 High2023-02-03
CVE-2022-25967 Eta 安全漏洞 — eta 8.1 High2023-01-30
CVE-2023-23619 Improper Control of Generation of Code ('Code Injection') in @asyncapi/modelina — modelina 10.0 Critical2023-01-26
CVE-2022-25894 UFLO 代码注入漏洞 — com.bstek.uflo:uflo-core 9.8 Critical2023-01-25
CVE-2022-25860 simple-git 安全漏洞 — simple-git 8.1 High2023-01-24
CVE-2022-34456 Dell EMC Metro node 代码注入漏洞 — Metro node 8.8 High2023-01-18
CVE-2023-22731 Improper Control of Generation of Code in Twig rendered views in shopware — platform 10.0 Critical2023-01-17
CVE-2023-0297 Code Injection in pyload/pyload — pyload/pyload 8.3 -2023-01-14
CVE-2023-0022 Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP) — BusinessObjects Business Intelligence platform (Analysis edition for OLAP) 9.9 Critical2023-01-10
CVE-2023-0048 Code Injection in lirantal/daloradius — lirantal/daloradius 8.8 -2023-01-04
CVE-2015-10009 nterchange code_caller_controller.php getContent code injection — nterchange 5.5 Medium2023-01-02
CVE-2022-23474 editor.js contains Code Injection — editor.js 6.1 Medium2022-12-15
CVE-2022-23503 TYPO3 vulnerable to Arbitrary Code Execution via Form Framework — typo3 7.5 High2022-12-14
CVE-2022-41264 SAP Basis 代码注入漏洞 — BASIS 8.8 High2022-12-13
CVE-2022-4223 pgAdmin 代码注入漏洞 — pgadmin4 8.8 -2022-12-13
CVE-2022-46157 Remote php code execution in Akeneo PIM — pim-community-dev 8.8 High2022-12-09
CVE-2022-46166 Spring Boot Admins integrated notifier support allows arbitrary code execution — spring-boot-admin 8.1 High2022-12-09
CVE-2022-46742 PaddlePaddle 代码注入漏洞 — PaddlePaddle 10.0 Critical2022-12-07
CVE-2022-42699 WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Remote Code Execution (RCE) — Easy WP SMTP 9.1 Critical2022-12-06
CVE-2022-46333 Proofpoint Enterprise Protection perl eval() arbitrary command execution — enterprise_protection 7.2 High2022-12-06
CVE-2022-46161 Code injection in pdfmake — pdfmake 10.0 Critical2022-12-06
CVE-2022-23465 SwiftTerm vulnerable to arbitrary command execution — SwiftTerm 7.1 High2022-12-02

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1298 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.