Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute
vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototyp
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starti
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-s
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code duri
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console fea
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex
The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the fo
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent nod
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is d
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not check
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users
A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary c
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when
NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu
A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explic
SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGe
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c
nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handleb
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that
Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis
In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al
In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started