A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of
A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted elem
A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T
A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the compon
A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend
A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unkn
A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an un
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks
A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the
A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functional
A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functi
A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/
A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processin
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decod
A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlR
A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some
A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, u
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileg
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerabilit
Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae4
Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/bati
Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issu
CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintende
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows
LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveC
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modul
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / da
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has
Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute work
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. Th
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with th
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code i
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started