An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not appl
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent al
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remo
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, A
AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline file
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection en
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges o
The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated us
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation
Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t
AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut
Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitra
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluate
The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitra
Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitr
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t
BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u
Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar
Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code
Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticate
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started