CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,168
Total CVEs
104
Critical
1,275
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
220
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,168)

CVE-2026-25520
10.0

SandboxJS versions before 0.8.29 have a critical sandbox escape vulnerability that allows attackers to obtain the host's Function constructor and exec...

Feb 6, 2026
CVE-2026-25586
10.0

This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandboxing by shadowing...

Feb 6, 2026
CVE-2025-20265
10.0

This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary shell commands wit...

Aug 14, 2025
CVE-2025-20337
KEV 10.0

An unauthenticated remote code execution vulnerability in Cisco ISE and ISE-PIC allows attackers to execute arbitrary commands as root without credent...

Jul 16, 2025
CVE-2025-20281
KEV EPSS 24% 10.0

An unauthenticated remote code execution vulnerability in Cisco ISE and ISE-PIC API allows attackers to execute arbitrary commands as root without cre...

Jun 25, 2025
CVE-2024-42472
10.0

This vulnerability in Flatpak allows malicious or compromised applications using persistent directories to escape sandbox restrictions and access/writ...

Aug 15, 2024
CVE-2024-42489
10.0

This CVE describes a critical remote code execution vulnerability in Pro Macros for XWiki. Attackers with view rights on specific pages or edit/commen...

Aug 12, 2024
CVE-2023-1523
10.0

This vulnerability allows malicious snaps to inject terminal input via TIOCLINUX ioctl, potentially executing arbitrary commands outside the snap sand...

Sep 1, 2023
CVE-2022-24760
10.0

CVE-2022-24760 is a critical Remote Code Execution vulnerability in Parse Server caused by prototype pollution in DatabaseController.js. It allows att...

Mar 12, 2022
CVE-2021-41163
10.0

CVE-2021-41163 is a critical remote code execution vulnerability in Discourse that allows attackers to execute arbitrary code on affected servers thro...

Oct 20, 2021
CVE-2021-21242
10.0

CVE-2021-21242 is a critical pre-authentication remote code execution vulnerability in OneDev devops platform. Attackers can exploit insecure deserial...

Jan 15, 2021
CVE-2021-21243
10.0

This vulnerability in OneDev allows unauthenticated remote code execution via insecure deserialization in Kubernetes REST endpoints. Attackers can exp...

Jan 15, 2021
CVE-2020-26282
10.0

CVE-2020-26282 is a critical Server-Side Template Injection vulnerability in BrowserUp Proxy that allows unauthenticated attackers to inject arbitrary...

Dec 24, 2020
CVE-2024-46986
9.9

CVE-2024-46986 is an arbitrary file write vulnerability in Camaleon CMS that allows authenticated users to write files to any location on the web serv...

Sep 18, 2024
CVE-2023-37462
9.9

This vulnerability in XWiki Platform allows attackers with view rights on the SkinsCode.XWikiSkinsSheet document to escalate privileges to programming...

Jul 14, 2023
CVE-2023-36470
9.9

CVE-2023-36470 is a critical remote code execution vulnerability in XWiki Platform that allows attackers to inject and execute malicious code with pro...

Jun 29, 2023
CVE-2023-29524
9.9

This vulnerability allows authenticated users without script or programming rights to execute arbitrary Groovy code on XWiki servers by adding malicio...

Apr 19, 2023
CVE-2023-29526
9.9

This vulnerability in XWiki Platform allows attackers to bypass access controls and execute arbitrary code through specially crafted comments containi...

Apr 19, 2023
CVE-2023-29510
9.9

This vulnerability allows any user with edit access to at least one document (including their own profile by default) to inject malicious code through...

Apr 19, 2023
CVE-2023-29514
9.9

CVE-2023-29514 is a critical remote code execution vulnerability in XWiki Platform where any user with document edit rights can execute arbitrary code...

Apr 19, 2023
CVE-2023-29516
9.9

CVE-2023-29516 is a critical remote code execution vulnerability in XWiki Platform where any user with view rights on the XWiki.AttachmentSelector pag...

Apr 19, 2023
CVE-2023-29518
9.9

This vulnerability allows any user with view rights in XWiki Platform to execute arbitrary Groovy, Python, or Velocity code, leading to full compromis...

Apr 19, 2023
CVE-2023-29522
9.9

CVE-2023-29522 is a critical remote code execution vulnerability in XWiki Platform that allows any user with view rights to execute arbitrary script m...

Apr 19, 2023
CVE-2023-25616
9.9

CVE-2023-25616 is a code injection vulnerability in SAP Business Objects Business Intelligence Platform's Central Management Console (CMC) that allows...

Mar 14, 2023
CVE-2023-27479
9.9

CVE-2023-27479 is a critical remote code execution vulnerability in XWiki Platform where any user with view rights can execute arbitrary Groovy, Pytho...

Mar 7, 2023
CVE-2020-10208
9.9

This CVE describes a command injection vulnerability in EntoneWebEngine used by Amino Communications set-top boxes. Authenticated remote attackers can...

Dec 30, 2020
CVE-2026-27194
9.8

CVE-2026-27194 is a remote code execution vulnerability in D-Tale's /save-column-filter endpoint that allows attackers to execute arbitrary code on vu...

Feb 21, 2026
CVE-2026-25814
9.8

PlaciPy version 1.0.0 passes user-controlled query parameters directly into DynamoDB query/filter construction without validation or sanitization. Thi...

Feb 9, 2026
CVE-2025-14707
9.8

This is a critical command injection vulnerability in Shiguangwu sgwbox N3 version 2.0.25 that allows remote attackers to execute arbitrary commands o...

Dec 15, 2025
CVE-2025-14706
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 devices through command injection in the NETREBOOT In...

Dec 15, 2025
CVE-2025-14705
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 NAS devices through command injection in the SHARESER...

Dec 15, 2025
CVE-2025-64428
9.8

This CVE describes a JNDI injection vulnerability in Dataease, an open-source data visualization tool. Attackers can exploit this to execute arbitrary...

Nov 20, 2025
CVE-2025-56266
9.8

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code by manipulating the Host header in HTTP re...

Sep 8, 2025
CVE-2024-46997
9.8

This vulnerability allows remote attackers to execute arbitrary commands on DataEase servers by crafting malicious H2 database connection strings. Any...

Sep 23, 2024
CVE-2024-46983
9.8

CVE-2024-46983 is a critical deserialization vulnerability in SOFA Hessian that allows attackers to bypass blacklist protections and execute arbitrary...

Sep 19, 2024
CVE-2024-39227
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code or perform directory traversal attacks on affected GL-iNet routers via t...

Aug 6, 2024
CVE-2024-39704
9.8

This vulnerability allows remote attackers to execute arbitrary code on clients running vulnerable versions of Melty Blood: Actress Again: Current Cod...

Jun 28, 2024
CVE-2024-39243
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on skycaiji 2.8 systems by sending specially crafted POST requests to th...

Jun 26, 2024
CVE-2024-37759
9.8

DataGear v5.0.0 and earlier contains a Spring Expression Language (SpEL) injection vulnerability in the Data Viewing interface. This allows authentica...

Jun 24, 2024
CVE-2024-34919
9.8

This vulnerability allows attackers to upload malicious files to the Pisay Online E-Learning System, which can lead to remote code execution. Attacker...

May 17, 2024
CVE-2023-51388
9.8

This vulnerability allows remote code execution in Hertzbeat monitoring systems through AviatorScript injection. Attackers can execute arbitrary stati...

Feb 22, 2024
CVE-2023-51653
9.8

This vulnerability in Hertzbeat allows remote code execution via JNDI injection in the JMX connector implementation. Attackers can exploit the /api/mo...

Feb 22, 2024
CVE-2023-22527
9.8

This is a critical template injection vulnerability (CWE-74) in older Confluence Data Center and Server versions that allows unauthenticated attackers...

Jan 16, 2024
CVE-2024-0552
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on servers running Intumit SmartRobot's web framework. Attack...

Jan 15, 2024
CVE-2024-21623
9.8

CVE-2024-21623 is an expression injection vulnerability in OTClient's GitHub Actions workflow that allows remote code execution on GitHub runners. Att...

Jan 2, 2024
CVE-2023-43364
9.8

CVE-2023-43364 is a critical remote code execution vulnerability in Searchor's main.py that uses eval() on untrusted CLI input. This allows attackers ...

Dec 12, 2023
CVE-2023-46456
9.8

This vulnerability allows remote attackers to execute arbitrary shell commands on GL.iNET GL-AR300M routers by exploiting improper input validation in...

Dec 12, 2023
CVE-2023-49214
9.8

CVE-2023-49214 is a chat template injection vulnerability in Usedesk that allows attackers to inject malicious templates into chat interfaces. This af...

Nov 23, 2023
CVE-2023-5340
9.8

This vulnerability in the Five Star Restaurant Menu and Food Ordering WordPress plugin allows unauthenticated attackers to perform PHP Object Injectio...

Nov 20, 2023
CVE-2022-46337
9.8

CVE-2022-46337 is an LDAP authentication bypass vulnerability in Apache Derby database systems. Attackers can use specially crafted usernames to bypas...

Nov 20, 2023

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,168 CVEs classified as CWE-74, with 104 rated critical and 1,275 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free