CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,158
Total CVEs
102
Critical
1,268
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
219
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,158)

CVE-2022-47583
9.8

CVE-2022-47583 is a terminal character injection vulnerability in Mintty terminal emulator that allows attackers to execute arbitrary code by sending ...

Oct 19, 2023
CVE-2022-24989
9.8

CVE-2022-24989 is a critical remote code execution vulnerability in TerraMaster NAS devices that allows attackers to execute arbitrary commands as roo...

Aug 20, 2023
CVE-2023-39662
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of llama_index. Attackers can exploit the ...

Aug 15, 2023
CVE-2023-38896
9.8

This vulnerability in LangChain allows remote attackers to execute arbitrary code through the from_math_prompt and from_colored_object_prompt function...

Aug 15, 2023
CVE-2023-39659
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of LangChain. Attackers can exploit the Py...

Aug 15, 2023
CVE-2023-36210
9.8

MotoCMS 3.4.3 contains a Server-Side Template Injection (SSTI) vulnerability in the Store Category Template via the keyword parameter. This allows att...

Aug 1, 2023
CVE-2023-36188
9.8

This vulnerability in LangChain version 0.0.64 allows remote attackers to execute arbitrary Python code through the PALChain parameter. Attackers can ...

Jul 6, 2023
CVE-2023-32314
9.8

CVE-2023-32314 is a critical sandbox escape vulnerability in vm2 that allows attackers to bypass sandbox protections and execute arbitrary code on the...

May 15, 2023
CVE-2023-29827
9.8

CVE-2023-29827 is a server-side template injection vulnerability in ejs v3.1.9 that allows attackers to execute arbitrary code if they can control tem...

May 4, 2023
CVE-2023-30547
9.8

This vulnerability in vm2 sandbox allows attackers to escape the sandbox environment and execute arbitrary code on the host system by exploiting impro...

Apr 17, 2023
CVE-2023-29374
9.8

This vulnerability in LangChain's LLMMathChain allows attackers to inject malicious prompts that execute arbitrary Python code via the exec() method. ...

Apr 5, 2023
CVE-2023-27040
9.8

Simple Image Gallery v1.0 contains a remote code execution vulnerability in the username parameter that allows attackers to execute arbitrary code on ...

Mar 16, 2023
CVE-2023-26261
9.8

This vulnerability in UBIKA WAAP Gateway/Cloud allows attackers to bypass authentication by stealing another user's session through blind XPath inject...

Mar 8, 2023
CVE-2023-25613
9.8

An LDAP injection vulnerability in Apache Kerby's LdapIdentityBackend allows attackers to manipulate LDAP queries through user-controlled input. This ...

Feb 20, 2023
CVE-2022-34914
9.8

CVE-2022-34914 is an injection vulnerability in Webswing that allows attackers to manipulate the X-Forwarded-For header to inject arbitrary arguments ...

Jul 8, 2022
CVE-2020-28246
9.8

This CVE describes a Server-Side Template Injection vulnerability in Form.io version 2.0.0 that allows remote code execution when deleting the default...

Jun 2, 2022
CVE-2022-25420
9.8

CVE-2022-25420 is a CRLF injection vulnerability in NTT Resonant's goo blog App Web Application 1.0 that allows attackers to execute arbitrary code vi...

Mar 29, 2022
CVE-2022-26205
9.8

CVE-2022-26205 is a critical remote code execution vulnerability in Marky software that allows attackers to execute arbitrary code by injecting malici...

Mar 27, 2022
CVE-2021-44550
9.8

CVE-2021-44550 is an incorrect access control vulnerability in Stanford CoreNLP's NERServlet that allows unauthenticated remote attackers to bypass au...

Feb 24, 2022
CVE-2022-25337
9.8

This vulnerability in Ibexa DXP allows attackers to perform injection attacks via image filenames. It affects systems running ezsystems/ezpublish-kern...

Feb 18, 2022
CVE-2021-43185
9.8

CVE-2021-43185 is a Host header injection vulnerability in JetBrains YouTrack that allows attackers to manipulate HTTP Host headers to perform web cac...

Nov 9, 2021
CVE-2021-41170
9.8

This vulnerability in neoan3-apps/template allows remote code execution through template injection. Attackers can pass callable values (closures) that...

Nov 8, 2021
CVE-2021-38294
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on Apache Storm Nimbus servers by sending specially crafted T...

Oct 25, 2021
CVE-2021-38458
9.8

A path traversal vulnerability in Moxa MXview Network Management software allows attackers to create or overwrite critical files, potentially leading ...

Oct 12, 2021
CVE-2021-41862
9.8

CVE-2021-41862 is a critical remote code execution vulnerability in AviatorScript that allows attackers to execute arbitrary code by crafting maliciou...

Oct 2, 2021
CVE-2021-41392
9.8

CVE-2021-41392 is a critical remote code execution vulnerability in Boost Note desktop application. Attackers can send malicious IPC messages to explo...

Sep 17, 2021
CVE-2021-20509
9.8

CVE-2021-20509 is a CSV injection vulnerability in IBM Maximo Asset Management that allows remote attackers to execute arbitrary commands on affected ...

Aug 12, 2021
CVE-2021-3169
9.8

This vulnerability in Jumpserver allows attackers to create connection tokens through an unprotected API endpoint, which can then be used to access se...

Jul 23, 2021
CVE-2018-25016
9.8

CVE-2018-25016 is a Host Header Injection vulnerability in Greenbone Security Assistant (GSA) and Greenbone OS (GOS) that allows attackers to manipula...

Jun 21, 2021
CVE-2021-27730
9.8

CVE-2021-27730 is an argument injection vulnerability in Accellion FTA that allows attackers to execute arbitrary commands via crafted POST requests t...

Mar 2, 2021
CVE-2021-3197
9.8

This vulnerability allows remote attackers to execute arbitrary shell commands on SaltStack Salt servers via shell injection in the salt-api SSH clien...

Feb 27, 2021
CVE-2020-35775
9.8

CVE-2020-35775 is an LDAP injection vulnerability in CITSmart ITSM software that allows attackers to manipulate LDAP queries through user input. This ...

Feb 15, 2021
CVE-2020-15690
9.8

CVE-2020-15690 is a CRLF injection vulnerability in Nim's asyncftpclient library that allows attackers to inject arbitrary commands into FTP sessions ...

Jan 30, 2021
CVE-2024-27708
9.6

This CVE describes an iframe injection vulnerability in MyNET v.26.06 and earlier that allows remote attackers to execute arbitrary code via the src p...

Dec 22, 2025
CVE-2024-32986
9.6

This vulnerability allows malicious Progressive Web Apps (PWAs) to inject arbitrary code execution commands into desktop configuration files on Linux ...

May 3, 2024
CVE-2023-39655
9.6

This host header injection vulnerability in @perfood/couch-auth allows attackers to send password reset links that redirect to attacker-controlled ser...

Jan 3, 2024
CVE-2023-33241
9.6

This vulnerability affects cryptocurrency wallets implementing GG18 or GG20 threshold signature schemes (TSS). An attacker can extract the full ECDSA ...

Aug 9, 2023
CVE-2021-21247
9.6

This vulnerability allows authenticated attackers to achieve remote code execution on OneDev DevOps platforms by exploiting insecure deserialization i...

Jan 15, 2021
CVE-2021-21249
9.6

CVE-2021-21249 is a post-authentication remote code execution vulnerability in OneDev DevOps platform. It allows authenticated attackers to execute ar...

Jan 15, 2021
CVE-2025-32711
9.3

This CVE describes an AI command injection vulnerability in Microsoft 365 Copilot that allows unauthorized attackers to execute arbitrary commands and...

Jun 11, 2025
CVE-2022-31631
9.1

This vulnerability in PHP's PDO::quote() function for SQLite allows SQL injection when processing overly long user-supplied strings. It affects PHP ap...

Feb 12, 2025
CVE-2024-39784
9.1

This CVE describes multiple command injection vulnerabilities in the Wavlink AC3000 router's nas.cgi add_dir() functionality. An authenticated attacke...

Jan 14, 2025
CVE-2024-36295
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers via a crafted HTTP request to the qos.cgi en...

Jan 14, 2025
CVE-2024-34544
9.1

This CVE describes a command injection vulnerability in the Wavlink AC3000 router's wireless.cgi AddMac() function. An authenticated attacker can exec...

Jan 14, 2025
CVE-2024-21797
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by sending specially crafted HTTP requests t...

Jan 14, 2025
CVE-2021-41128
9.1

CVE-2021-41128 is a CSV injection vulnerability in Hygeia that allows users to embed malicious formulas in exported CSV files. When these files are op...

Oct 6, 2021
CVE-2021-20736
9.1

This NoSQL injection vulnerability in GROWI wiki software allows attackers to manipulate database queries and access/modify stored data. It affects GR...

Jun 22, 2021
CVE-2026-24002
9.0

This vulnerability allows arbitrary code execution on Grist servers when using the pyodide sandbox flavor with untrusted spreadsheets. Attackers can r...

Jan 22, 2026
CVE-2024-39604
9.0

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink AC3000 routers by sending specially crafted HTTP requests. Attacke...

Jan 14, 2025
CVE-2023-36471
9.0

XWiki Commons HTML sanitizer vulnerability allows attackers without script rights to create phishing forms or embed malicious inputs that could lead t...

Jun 29, 2023

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,158 CVEs classified as CWE-74, with 102 rated critical and 1,268 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free