The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adver
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twi
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden par
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
Skype for Business Remote Code Execution Vulnerability
A remote code execution issue exists in HPE OneView.
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PH
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an
Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not proper
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridi
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injectio
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without saniti
An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Se
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote co
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code e
Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zeman
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older versi
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communicat
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who a
OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Sett
A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a
A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the fi
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemF
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver cod
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and ha
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started