Windows Search Service Elevation of Privilege Vulnerability
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co
In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage t
An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.
PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execu
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can defin
In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by pro
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper ha
In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages
BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand
SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in al
KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects
In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protectio
insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i
insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component
A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in th
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Gro
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec valu
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a v
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module con
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta
Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code
An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe
alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE)
An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started