SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2)
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateA
An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The imple
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and
An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privile
Microsoft DirectMusic Remote Code Execution Vulnerability
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. Th
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Conten
Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a sp
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracero
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection ag
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLI
Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerabl
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorke
Azure DevOps Server Remote Code Execution Vulnerability
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load a
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-G
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON str
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input da
An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel acce
An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial o
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due t
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules)
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploite
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multip
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in out
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.in
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in Yuga
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authentica
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote c
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote cod
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started