OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript mon
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits i
Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypas
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows
Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite all
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder all
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assis
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the exte
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring
Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a r
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /a
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result i
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the i
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or updat
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-defi
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux al
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allow
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.
Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerabi
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started