cwe-94
Safeguard articles tagged "cwe-94" — guides, analysis, and best practices for software supply chain and application security.
73 articles
CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-1340 affects Ivanti Endpoint Manager Mobile (EPMM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-08.
CVE-2009-0238: Microsoft Office Remote Code Execution
CVE-2009-0238 affects Microsoft Office and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-14.
CVE-2026-34197: Apache ActiveMQ Improper Input Validation Vulnerability
CVE-2026-34197 affects Apache ActiveMQ and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-16.
CVE-2008-4250: Microsoft Windows Buffer Overflow Vulnerability
CVE-2008-4250 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-20.
CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability
CVE-2025-67038 affects Lantronix EDS5000 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-23.
CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE-2026-15410 affects SonicWall SMA1000 Appliances and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-14.
CVE-2026-9198: IBM Langflow Code Injection Vulnerability
CVE-2026-9198 affects IBM Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-04.
CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability
CVE-2025-62593 affects Ray-Project Ray and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-17.
CVE-2026-72530: TrueConf Server Code Injection Vulnerability
CVE-2026-72530 affects TrueConf Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-20.
CVE-2026-60004: Gitea Code Injection Vulnerability
CVE-2026-60004 affects Gitea Gitea and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-25.
Follina (CVE-2022-30190): The Office Attack That Needed No Macros
A factual look at Follina, a 2022 Windows vulnerability abusing the MSDT protocol handler, which allowed code execution from a Word document without macros and therefore bypassed the standard defensive advice.
Spring4Shell (CVE-2022-22965): Class Loader Manipulation in Spring Framework
A factual look at Spring4Shell, the March 2022 remote code execution vulnerability in Spring Framework, including why its real-world impact was narrower than the initial Log4Shell comparisons suggested.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.