Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Inj
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Co
The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrar
MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a
SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicio
In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod
The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plu
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to exe
PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to exec
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl
An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageControl
The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including
Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code In
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t
Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets a
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including
A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injecti
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profile
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allow
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Co
Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In
Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i
The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affe
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code E
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected b
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown funct
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the functio
A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of
The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi
A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality o
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in
A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vuln
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o
A flaw has been found in ChenJinchuang Lin-CMS-TP5 up to 0.3.3. This vulnerability affects the function Upload of the fi
A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the l
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started