Falhas do tipo CWE-94

3.746 resultados
CVE-2024-36268HIGHApache InLong TubeMQ Client: Remote Code Execution vulnerabilityEPSS 1.2%CVE-2025-34061CRITICALPHPStudy 2016-2018 Backdoor Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-40522HIGHThere is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passeEPSS 1.2%CVE-2023-28333CRITICALMoodle: pix helper potential mustache code injection riskEPSS 1.2%CVE-2022-30194HIGHWindows WebBrowser Control Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-43542HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.2%CVE-2024-44623HIGHAn issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.EPSS 1.2%CVE-2023-28354CRITICALAn issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, speciEPSS 1.2%CVE-2021-29475CRITICALPDF export allows arbitrary file readsEPSS 1.2%CVE-2023-43625CRITICALA vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that couEPSS 1.2%CVE-2021-22150MEDIUMKibana code execution issueEPSS 1.2%CVE-2024-50450HIGHWordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Bypass Vulnerability vulnerabilityEPSS 1.2%CVE-2023-1283CRITICAL Code Injection in builderio/qwikEPSS 1.1%CVE-2026-24780HIGHAutoGPT is Vulnerable to RCE via Disabled Block ExecutionEPSS 1.1%CVE-2024-31032CRITICALAn issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitraEPSS 1.1%CVE-2026-30307CRITICALRoo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanismEPSS 1.1%CVE-2026-30305CRITICALSyntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism coEPSS 1.1%CVE-2026-30313CRITICALDSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechaniEPSS 1.1%CVE-2024-6507HIGHDeep Lake Kaggle command injectionEPSS 1.1%CVE-2025-53890CRITICALpyLoad vulnerable to remote code execution through js2py onCaptchaResultEPSS 1.1%