There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, una
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via
SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attack
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Androi
A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Andro
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to acces
A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(1
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi
A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content provi
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment,
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbi
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for th
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools r
Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCrite
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code e
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /m
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate pr
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For exam
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started