Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine conf
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-exp
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrat
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versio
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The s
Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability i
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual
An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are
Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in
Microsoft SharePoint Server Remote Code Execution Vulnerability
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromis
Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects al
Microsoft Exchange Server Remote Code Execution Vulnerability
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a cr
Microsoft Excel Remote Code Execution Vulnerability
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which
Microsoft Word Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses Y
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prio
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4
There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this v
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote att
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP'
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a
There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust s
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to s
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I
WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to
Microsoft Outlook Remote Code Execution Vulnerability
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to ex
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability wh
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution)
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this v
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execu
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an auth
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started