EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `Tabl
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `Lanc
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated re
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template I
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe process
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted sc
Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2
pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoa
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1
langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component.
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized file
An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remot
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. Th
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JD
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 para
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability
rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to
Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can
iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.
Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio
The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started