Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows
OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra
The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including,
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administ
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authentica
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'the
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administ
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrator
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not bl
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked func
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an
Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code inj
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v
Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,
A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code exec
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres
The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers
Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String express
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a
Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0
Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to writ
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inform
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started