A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. Affected by thi
A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been declared as problematic. This vul
A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been rated as problematic. This issue
A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. This vulne
A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown fun
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow c
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom pr
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Rep
Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3
A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 100
A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. T
Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of
Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the w
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wi
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.
A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users run
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't p
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u
Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RS
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Ve
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiM
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can ex
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can ex
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with t
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, t
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone
Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue aff
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started