Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XS
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus
A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e298
A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability
A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of t
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the
A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core
A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the
A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu
A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the fil
A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function dis
A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agent
A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpressio
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in
A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/page
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the functio
A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/s
Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru
ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera
A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. Thi
FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricte
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/
A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_code
A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This imp
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Po
A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutate
A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/ob
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/
A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of th
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the f
A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP
A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/e
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/f
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10
A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function Groovy
A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/wor
A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmart
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function Se
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminal
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attacke
The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflect
yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started