Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-26045 Moodle: moodle: improper validation in file restore functionality leading to remote code execution 7.2 High2026-02-21
CVE-2025-67979 WordPress WPForms Google Sheet Connector plugin <= 4.0.1 - Remote Code Execution (RCE) vulnerability — WPForms Google Sheet Connector 9.8AICriticalAI2026-02-20
CVE-2025-52744 WordPress Inpersttion For Theme plugin <= 1.0 - Arbitrary Code Execution vulnerability — Inpersttion For Theme 7.7 High2026-02-20
CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution — semantic-kernel 10.0 Critical2026-02-19
CVE-2025-71243 SPIP Saisies Plugin < 5.11.1 Remote Code Execution — Saisies pour formulaire 9.8 Critical2026-02-19
CVE-2026-25755 jsPDF has PDF Object Injection via Unsanitized Input in addJS Method — jsPDF 8.1 High2026-02-19
CVE-2026-25548 InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning — InvoicePlane 9.1 Critical2026-02-18
CVE-2026-27174 MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval — MajorDoMo 9.8 Critical2026-02-18
CVE-2025-14009 Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution — nltk/nltk 8.8AIHighAI2026-02-18
CVE-2025-61982 OpenCFD OpenFOAM 安全漏洞 — OpenFOAM 7.8 High2026-02-18
CVE-2025-33240 NVIDIA Megatron Bridge 代码注入漏洞 — Megatron-Bridge 7.8 High2026-02-18
CVE-2025-33239 NVIDIA Megatron Bridge 代码注入漏洞 — Megatron-Bridge 7.8 High2026-02-18
CVE-2025-33251 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2026-02-18
CVE-2025-33250 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2026-02-18
CVE-2025-33236 NVIDIA Nemo Framework 代码注入漏洞 — NeMo Framework 7.8 High2026-02-18
CVE-2026-2296 Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter — Product Addons for Woocommerce – Product Options with Custom Fields 7.2 High2026-02-18
CVE-2025-33042 Apache Avro Java SDK: Code injection on Java generated code — Apache Avro Java SDK 9.8 -2026-02-13
CVE-2026-26056 Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC — yoke 8.8 High2026-02-12
CVE-2026-25227 authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint — authentik 9.1 Critical2026-02-12
CVE-2026-26216 Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter — Crawl4AI 10.0 Critical2026-02-12
CVE-2026-0969 Arbitrary code execution in React server-side rendering of untrusted MDX content — Shared library 8.8 High2026-02-12
CVE-2020-37186 Chevereto 3.13.4 Core - Remote Code Execution — Chevereto 9.8 Critical2026-02-11
CVE-2020-37178 KeePass 2.44 - Denial of Service (PoC) — KeePass Password Safe 7.5 High2026-02-11
CVE-2026-1226 Schneider Electric EcoStruxure Building Operation Workstation 代码注入漏洞 — EcoStruxure Building Operation Workstation 7.8AIHighAI2026-02-11
CVE-2026-1560 Custom Block Builder – Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution — Custom Block Builder – Lazy Blocks 8.8 High2026-02-11
CVE-2025-14541 Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter — Lucky Wheel Giveaway 7.2 High2026-02-11
CVE-2026-21537 Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability — Microsoft Defender for Endpoint for Linux 8.8 High2026-02-10
CVE-2026-25807 Unauthenticated Remote Code Execution via P2P Sharing in ZAI-Shell — zai-shell 8.8 High2026-02-09
CVE-2026-1615 jsonpath 安全漏洞 — jsonpath 9.8 Critical2026-02-09
CVE-2026-25587 SandboxJS has a Sandbox Escape — SandboxJS 10.0 Critical2026-02-06

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.