Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generat
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker t
Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value
pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI
A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its A
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul
Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevat
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply re
NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, Stanford
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p
PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runti
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha
datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio
datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem
datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type v
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to byp
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Serv
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerabi
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config f
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can brea
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started