Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra:
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This i
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Cor
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionCont
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/i
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installatio
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 808
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution back
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addo
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not ap
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Executio
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Ba
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hiv
An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the servi
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted requ
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when ru
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. Th
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary cod
An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preaut
xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started