A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function e
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t
The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying
A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute
The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms all
A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t
A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code I
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can
The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22
The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi
Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject sys
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality tha
The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi
The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions u
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI
A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote co
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute
In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl
An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida
The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure B
Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulner
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started