A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via
A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attac
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all
The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f
The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S
Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin
Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arb
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject mal
A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute
Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-c
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a s
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through th
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator
An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Sal
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,
The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which
The administrator is able to configure an insecure captive portal script
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unau
Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affec
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected
Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to,
pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte
The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started