cwe-94
Safeguard articles tagged "cwe-94" — guides, analysis, and best practices for software supply chain and application security.
73 articles
CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerability
CVE-2025-1976 affects Broadcom Brocade Fabric OS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-04-28.
CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2025-4428 affects Ivanti Endpoint Manager Mobile (EPMM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-05-19.
CVE-2024-56145: Craft CMS Code Injection Vulnerability
CVE-2024-56145 affects Craft CMS Craft CMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-06-02.
CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability
CVE-2025-49704 affects Microsoft SharePoint and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.
CVE-2025-6204: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
CVE-2025-6204 affects Dassault Systèmes DELMIA Apriso and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-28.
CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
CVE-2025-37164 affects Hewlett Packard Enterprise (HPE) OneView and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-07.
CVE-2009-0556: Microsoft Office PowerPoint Code Injection Vulnerability
CVE-2009-0556 affects Microsoft Office and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-07.
CVE-2026-20045: Cisco Unified Communications Products Code Injection Vulnerability
CVE-2026-20045 affects Cisco Unified Communications Manager and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-21.
CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-1281 affects Ivanti Endpoint Manager Mobile (EPMM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-29.
CVE-2025-54068: Laravel Livewire Code Injection Vulnerability
CVE-2025-54068 affects Laravel Livewire and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-20.
CVE-2025-32432: Craft CMS Code Injection Vulnerability
CVE-2025-32432 affects Craft CMS Craft CMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-20.
CVE-2026-33017: Langflow Code Injection Vulnerability
CVE-2026-33017 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-25.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.