In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a com
Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 1
An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 befor
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to per
A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getC
A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn
Azure DevOps Server Spoofing Vulnerability
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable th
Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerab
A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown
A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown fu
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers t
A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web se
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated back
An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1
An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of t
A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/ind
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and m
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and ma
A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown
A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resul
Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is e
JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/java
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is
Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment var
Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as prob
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file L
A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle scr
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to exec
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system comm
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfm
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started