The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URL
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) a
Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Li
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the writ
The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.
The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,
The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec
The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading
A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionServ
A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an
A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function Ex
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file a
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via
The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote
SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code
File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .p
luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerabi
A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some u
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some
A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is
In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of th
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh
The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPres
The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update
The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via
A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of t
A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /
A vulnerability classified as critical was found in melMass comfy_mtb up to 0.1.4. Affected by this vulnerability is the
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary short
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker
Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attacke
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to exe
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content
There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticat
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scrip
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbit
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started