In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on
Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunn
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remot
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an atta
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versi
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versi
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a maliciou
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execu
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection v
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static page
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior t
The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to in
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a p
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data C
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user por
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, a
Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/
A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP co
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TB
Visual Studio Remote Code Execution Vulnerability
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiali
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code exe
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated atta
iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavata
Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be exe
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started