Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it i
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbit
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administ
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConf
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers
MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the applicati
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write f
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's S
The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker wa
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malic
A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Forc
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficien
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get pe
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file e
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by
Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-co
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, re
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration opt
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attack
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute py
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk co
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injectio
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserte
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execu
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF fi
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started