Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25887 Chartbrew: Remote Code Execution (RCE) via MongoDB Dataset Query — chartbrew 7.2 High2026-03-06
CVE-2026-28134 WordPress JetEngine plugin <= 3.7.2 - Remote Code Execution (RCE) vulnerability — JetEngine 9.8 -2026-03-05
CVE-2026-27984 WordPress Widget Options plugin <= 4.1.3 - Remote Code Execution (RCE) vulnerability — Widget Options 9.8 -2026-03-05
CVE-2026-22390 WordPress Builderall Builder for WordPress plugin <= 3.0.1 - Remote Code Execution (RCE) vulnerability — Builderall Builder for WordPress 9.8 -2026-03-05
CVE-2026-28783 Craft has a Twig Function Blocklist Bypass — cms 7.2AIHighAI2026-03-04
CVE-2025-59059 Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator — Apache Ranger 9.8AICriticalAI2026-03-03
CVE-2026-21853 AFFiNE: One-click Remote Code Execution through Custom URL Handling — AFFiNE 8.8 High2026-03-02
CVE-2026-3132 Master Addons for Elementor Premium <= 2.1.3 - Authenticated (Subscriber+) Remote Code Execution via render_preview — Master Addons for Elementor Premium 8.8 High2026-03-02
CVE-2026-3409 eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module code injection — db-gpt 7.3 High2026-03-02
CVE-2026-3395 MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection — CMS 7.3 High2026-03-01
CVE-2026-28425 Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs — cms 8.0 High2026-02-27
CVE-2026-21658 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD 9.8 -2026-02-27
CVE-2026-21657 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD 6.8 -2026-02-27
CVE-2026-21656 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD 6.8 -2026-02-27
CVE-2026-27966 Langflow has Remote Code Execution in CSV Agent — langflow 9.8 Critical2026-02-26
CVE-2026-27952 Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE) — agenta-api 8.8 High2026-02-26
CVE-2026-27498 n8n has Arbitrary Command Execution via File Write and Git Operations — n8n 8.8AIHighAI2026-02-25
CVE-2026-27577 n8n: Expression Sandbox Escape Leads to RCE — n8n 9.9AICriticalAI2026-02-25
CVE-2026-27497 n8n has Potential Remote Code Execution via Merge Node — n8n 8.8AIHighAI2026-02-25
CVE-2026-27495 n8n has a Sandbox Escape in its JavaScript Task Runner — n8n 8.5AIHighAI2026-02-25
CVE-2026-27493 n8n has Unauthenticated Expression Evaluation via Form Node — n8n 9.8AICriticalAI2026-02-25
CVE-2026-27701 LiveCodes vulnerable to JavaScript Injection via untrusted PR title in i18n-update-pull workflow — livecodes 6.1AIMediumAI2026-02-25
CVE-2026-1929 Advanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter — Advanced Woo Labels – Product Labels & Badges for WooCommerce 8.8 High2026-02-25
CVE-2026-27597 @enclave-vm/core is vulnerable to Sandbox Escape — enclave 10.0 Critical2026-02-25
CVE-2026-27744 SPIP tickets < 4.3.3 Unauthenticated RCE — tickets 9.8 Critical2026-02-25
CVE-2026-27745 SPIP interface_traduction_objets < 2.2.2 Authenticated RCE — interface_traduction_objets 8.8 High2026-02-25
CVE-2024-56373 Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information — Apache Airflow 8.0AIHighAI2026-02-24
CVE-2026-25797 ImageMagick vulnerable to Code injection via PostScript header in ps coders — ImageMagick 5.7 Medium2026-02-24
CVE-2025-9120 RCE vulnerability has been discovered in OpenText™ Carbonite Safe Server Backup. — Carbonite Safe Server Backup 9.8AICriticalAI2026-02-24
CVE-2026-27574 OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE — oneuptime 10.0 Critical2026-02-21

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.