Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-4506 Mindinventory MindSQL mindsql_core.py ask_db code injection — MindSQL 6.3 Medium2026-03-20
CVE-2026-3584 Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process — Kali Forms — Contact Form & Drag-and-Drop Builder 9.8 Critical2026-03-20
CVE-2026-33057 Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py — mesop 9.8 Critical2026-03-20
CVE-2026-33017 Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint — langflow 9.8 -2026-03-20
CVE-2026-29103 SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass — SuiteCRM 9.1 Critical2026-03-19
CVE-2026-29102 SuiteCRM has Authenticated RCE in Modules — SuiteCRM 7.2 High2026-03-19
CVE-2026-30875 Chamilo LMS: Authenticated RCE via H5P Import — chamilo-lms 8.8 High2026-03-16
CVE-2025-15540 Authenticated RCE in Raytha CMS — Raytha 7.2AIHighAI2026-03-16
CVE-2026-3476 Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 — SOLIDWORKS Desktop 7.8 High2026-03-16
CVE-2025-14287 Command Injection in mlflow/mlflow — mlflow/mlflow 9.8 -2026-03-15
CVE-2026-26954 SandboxJS has a Sandbox Escape — SandboxJS 10.0 Critical2026-03-13
CVE-2026-32414 WordPress Advanced Woo Labels plugin <= 2.36 - Remote Code Execution (RCE) vulnerability — Advanced Woo Labels 9.8 -2026-03-13
CVE-2026-32367 WordPress Modal Dialog plugin <= 3.5.16 - Remote Code Execution (RCE) vulnerability — Modal Dialog 9.8 -2026-03-13
CVE-2026-32304 Locutus: RCE via unsanitized input in create_function() — locutus 9.8 Critical2026-03-12
CVE-2026-4039 OpenClaw Skill Env applySkillConfigenvOverrides code injection — OpenClaw 6.3 Medium2026-03-12
CVE-2026-3968 AutohomeCorp frostmourne Oracle Nashorn JavaScript ExpressionRule.java scriptEngine.eval code injection — frostmourne 6.3 Medium2026-03-12
CVE-2026-3955 elecV2P jsfile Endpoint wbjs.js runJSFile code injection — elecV2P 6.3 Medium2026-03-11
CVE-2019-25468 NetGain EM Plus 10.1.68 Remote Code Execution via script_test.jsp — NetGain EM Plus 9.8 Critical2026-03-11
CVE-2026-31857 CraftCMS has an RCE vulnerability via relational conditionals in the control panel — cms 8.8AIHighAI2026-03-11
CVE-2026-31861 Shell Command Injection in Git Routes [CloudCLI UI] — claudecodeui 8.8AIHighAI2026-03-11
CVE-2026-20892 Micro Research MR-GM5L-S1和Micro Research MR-GM5A-L1 代码注入漏洞 — MR-GM5L-S1 7.2AIHighAI2026-03-11
CVE-2026-2273 Schneider Electric EcoStruxure Automation Expert 代码注入漏洞 — EcoStruxure™ Automation Expert 7.8AIHighAI2026-03-10
CVE-2026-30960 RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface — rssn 9.8AICriticalAI2026-03-10
CVE-2026-30887 OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE — oneuptime 10.0 Critical2026-03-09
CVE-2026-3352 Easy PHP Settings <= 1.0.4 - Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting — Easy PHP Settings 7.2 High2026-03-07
CVE-2026-29075 Mesa: Checking out of untrusted code in `benchmarks.yml` workflow may lead to code execution in privileged runner — mesa 8.3 High2026-03-06
CVE-2026-2830 WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath' — WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets 6.1 Medium2026-03-06
CVE-2026-29039 changedetection.io: XPath - Arbitrary File Read via unparsed-text() — changedetection.io 6.5 -2026-03-06
CVE-2026-28801 Natro Macro: Code Injection through Pattern/Path files — NatroMacro 6.6 Medium2026-03-06
CVE-2026-25888 Chartbrew: Remote Code Execution (RCE) via Vulnerable API — chartbrew 8.8 High2026-03-06

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.