CWE-94 对生成代码的控制不恰当(代码注入) 类弱点 1742 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-94 指代码注入漏洞,属于输入验证缺陷。攻击者通过向程序提供恶意构造的外部输入,利用未正确过滤的特殊字符或代码片段,篡改预期代码逻辑或注入可执行指令,从而劫持系统控制权。开发者应避免直接拼接用户输入,采用白名单验证机制,并使用参数化查询或沙箱环境隔离执行上下文,确保输入数据的合法性与安全性,从根本上阻断恶意代码的注入路径。
$MessageFile = "messages.out"; if ($_GET["action"] == "NewMessage") { $name = $_GET["name"]; $message = $_GET["message"]; $handle = fopen($MessageFile, "a+"); fwrite($handle, "<b>$name</b> says '$message'<hr>\n"); fclose($handle); echo "Message Saved!<p>\n"; } else if ($_GET["action"] == "ViewMessages") { include($MessageFile); }
name=h4x0r message=%3C?php%20system(%22/bin/ls%20-l%22);?%3E
use CGI qw(:standard); sub config_file_add_key { my ($fname, $key, $arg) = @_; # code to add a field/key to a file goes here } sub config_file_set_key { my ($fname, $key, $arg) = @_; # code to set key to a particular file goes here } sub config_file_delete_key { my ($fname, $key, $arg) = @_; # code to delete key from a particular file goes here } sub handleConfigAction { my ($fname, $action) = @_; my $key = param('key'); my $val = param('val'); # this is super-efficient code, especially if you have to invoke # any one of dozens of different functions! my $code = "config_file_$action_key(\$fnam
add_key(",","); system("/bin/ls");
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-12419 | WordPress plugin CF7 WOW Styler 代码注入漏洞 — WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms | 6.5 | Medium | 2025-01-07 |
| CVE-2024-11733 | WordPress plugin The WordPress Popular Posts 代码注入漏洞 — WP Popular Posts | 7.3 | High | 2025-01-03 |
| CVE-2024-56803 | Ghostty 代码注入漏洞 — ghostty | 6.6 | - | 2024-12-31 |
| CVE-2024-12238 | WordPress plugin Ninja Forms 代码注入漏洞 — Ninja Forms – The Contact Form Builder That Grows With You | 6.3 | Medium | 2024-12-29 |
| CVE-2024-12908 | Delinea Secret Server 安全漏洞 — Secret Server | 6.9 | Medium | 2024-12-26 |
| CVE-2024-12952 | comfy_mtb 安全漏洞 — comfy_mtb | 6.3 | Medium | 2024-12-26 |
| CVE-2024-12652 | Intumit SmartRobot Conversational AI Platform 安全漏洞 — SmartRobot′s Conversational AI Platform | 8.8 | - | 2024-12-26 |
| CVE-2024-12900 | FoxCMS 注入漏洞 — FoxCMS | 6.3 | Medium | 2024-12-23 |
| CVE-2024-11977 | WordPress plugin The kk Star Ratings 代码注入漏洞 — kk Star Ratings – Rate Post & Collect User Feedbacks | 7.3 | High | 2024-12-21 |
| CVE-2024-56334 | systeminformation 代码注入漏洞 — systeminformation | 7.8 | High | 2024-12-20 |
| CVE-2024-56333 | Onyxia 代码注入漏洞 — onyxia | 9.9 | - | 2024-12-20 |
| CVE-2024-56327 | pyrage 代码注入漏洞 — pyrage | 7.5 | - | 2024-12-19 |
| CVE-2024-12729 | Sophos Firewall 安全漏洞 — Sophos Firewall | 8.8 | High | 2024-12-19 |
| CVE-2024-12789 | PbootCMS 注入漏洞 — PbootCMS | 6.3 | Medium | 2024-12-19 |
| CVE-2024-9154 | HMS Ewon Flexy 205 安全漏洞 — Ewon Flexy 205 | 9.8 | - | 2024-12-19 |
| CVE-2024-11740 | WordPress plugin Download Manager 代码注入漏洞 — Download Manager | 7.3 | High | 2024-12-19 |
| CVE-2024-56145 | Craft CMS 代码注入漏洞 — cms | 9.8 | - | 2024-12-18 |
| CVE-2024-56051 | WordPress plugin WPLMS 代码注入漏洞 — WPLMS | 8.5 | High | 2024-12-18 |
| CVE-2024-21546 | laravel-filemanager 安全漏洞 — unisharp/laravel-filemanager | 9.8 | Critical | 2024-12-18 |
| CVE-2024-55661 | Laravel Pulse 安全漏洞 — pulse | 8.8 | - | 2024-12-13 |
| CVE-2024-21577 | ComfyUI_AceNodes 安全漏洞 — ComfyUI-Ace-Nodes | 10.0 | Critical | 2024-12-13 |
| CVE-2024-21576 | ComfyUI Bmad Nodes 安全漏洞 — ComfyUI-Bmad-Nodes | 10.0 | Critical | 2024-12-13 |
| CVE-2024-11012 | WordPress plugin Notibar 代码注入漏洞 — Notibar – Notification Bar for WordPress | 6.3 | Medium | 2024-12-13 |
| CVE-2024-12417 | WordPress plugin Simple Link Directory 代码注入漏洞 — Simple Link Directory | 6.5 | Medium | 2024-12-13 |
| CVE-2024-12421 | WordPress plugin The Coupon Affiliates 代码注入漏洞 — Coupon Affiliates – Affiliate Plugin for WooCommerce | 6.5 | Medium | 2024-12-13 |
| CVE-2024-12420 | WordPress plugin WPMobile.App 代码注入漏洞 — WPMobile.App | 6.5 | Medium | 2024-12-13 |
| CVE-2024-12333 | WordPress plugin WoodMart 代码注入漏洞 — Woodmart | 6.5 | Medium | 2024-12-12 |
| CVE-2024-21574 | ComfyUI-Manager 安全漏洞 — ComfyUI-Manager | 10.0 | Critical | 2024-12-12 |
| CVE-2024-10910 | WordPress plugin Grid Plus 代码注入漏洞 — Grid Plus – Unlimited grid layout | 7.3 | High | 2024-12-12 |
| CVE-2024-54152 | Angular 代码注入漏洞 — angular-expressions | 10.0 | - | 2024-12-10 |
CWE-94(对生成代码的控制不恰当(代码注入)) 是常见的弱点类别,本平台收录该类弱点关联的 1742 条 CVE 漏洞。