D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users c
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious e
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a mal
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary cod
Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injecti
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.j
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabl
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persisten
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instanc
php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to exec
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary c
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability c
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. W
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code e
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file.
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file format
An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malic
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote att
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attacke
A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management S
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vuln
An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgr
Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to e
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started