This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1.
Microsoft Power Automate Remote Code Execution Vulnerability
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, ma
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2At
IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrar
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, m
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.
Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a
NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i
NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i
An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex
A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di
A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS dist
A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary
NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code inject
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code
NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker coul
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could c
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a co
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an
Delta Electronics COMMGR has Code Injection vulnerability.
NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a
NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker m
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attack
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data cre
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow pot
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missi
Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started