cwe-94
Safeguard articles tagged "cwe-94" — guides, analysis, and best practices for software supply chain and application security.
73 articles
CVE-2023-29492: Novi Survey Insecure Deserialization Vulnerability
CVE-2023-29492 affects Novi Survey Novi Survey and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-04-13.
CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
CVE-2023-25717 affects Ruckus Wireless Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-05-12.
CVE-2023-3519: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVE-2023-3519 affects Citrix NetScaler ADC and NetScaler Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-07-19.
CVE-2023-33246: Apache RocketMQ Command Execution Vulnerability
CVE-2023-33246 affects Apache RocketMQ and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-09-06.
CVE-2018-14667: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
CVE-2018-14667 affects Red Hat JBoss RichFaces Framework and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-09-28.
CVE-2023-6548: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVE-2023-6548 affects Citrix NetScaler ADC and NetScaler Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-17.
CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2024-21351 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-02-13.
CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
CVE-2021-44529 affects Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-03-25.
CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability
CVE-2023-24955 affects Microsoft SharePoint Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-03-26.
CVE-2024-20359: Cisco ASA and FTD Privilege Escalation Vulnerability
CVE-2024-20359 affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-04-24.
CVE-2022-24816: OSGeo GeoServer JAI-EXT Code Injection Vulnerability
CVE-2022-24816 affects OSGeo JAI-EXT and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-06-26.
CVE-2025-23209: Craft CMS Code Injection Vulnerability
CVE-2025-23209 affects Craft CMS Craft CMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-20.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.