Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitr
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a l
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑p
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix
Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 a
A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTime
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrar
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrar
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta
The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side templ
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows user
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch
Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i
Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Sc
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to impro
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execu
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation tha
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plug
ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Grem
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attacker
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role w
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipar
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 expos
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started