Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs w
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i
A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope
Remote attackers can execute arbitrary code in the context of the vulnerable service process.
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Co
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote comman
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag
A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handli
A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default c
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user
A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple version
A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin.
A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifical
Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page.
WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the t
Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed
HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there
Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This i
Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .m
In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" par
The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system()
lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i
PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture.
PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower
A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a
Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerabi
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,
A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e
AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictabl
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulner
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 v
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, an
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc
Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-du
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm.
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj
In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injectio
PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaSh
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started