An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page
The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the veri
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validatio
Azure CycleCloud Remote Code Execution Vulnerability
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t
A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backe
A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulne
A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in
The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows a
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization
Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence
Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code
Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerabi
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conv
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function l
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 1
Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender
Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection
Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitra
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL para
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Inj
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to tr
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker
An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to
OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UT
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote a
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started