The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows t
This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is
JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to exec
Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticat
A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) tha
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a loca
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish E
Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a d
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Def
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(),
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine co
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remot
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Aut
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a
An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on t
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Mac
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code inj
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead t
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary comman
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalat
Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbit
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Bi
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started