IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IB
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_con
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php fi
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - vers
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary co
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mecha
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An att
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of c
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, vi
BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashel
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leve
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager S
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d
Microsoft SharePoint Remote Code Execution Vulnerability
Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because th
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/produc
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" fi
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attacker
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Cod
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticate
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained acc
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be
The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Condit
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neu
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize t
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to exe
Microsoft SharePoint Server Remote Code Execution Vulnerability
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application.
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started