CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,158)
CVE-2022-47583 is a terminal character injection vulnerability in Mintty terminal emulator that allows attackers to execute arbitrary code by sending ...
Oct 19, 2023CVE-2022-24989 is a critical remote code execution vulnerability in TerraMaster NAS devices that allows attackers to execute arbitrary commands as roo...
Aug 20, 2023This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of llama_index. Attackers can exploit the ...
Aug 15, 2023This vulnerability in LangChain allows remote attackers to execute arbitrary code through the from_math_prompt and from_colored_object_prompt function...
Aug 15, 2023This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of LangChain. Attackers can exploit the Py...
Aug 15, 2023MotoCMS 3.4.3 contains a Server-Side Template Injection (SSTI) vulnerability in the Store Category Template via the keyword parameter. This allows att...
Aug 1, 2023This vulnerability in LangChain version 0.0.64 allows remote attackers to execute arbitrary Python code through the PALChain parameter. Attackers can ...
Jul 6, 2023CVE-2023-32314 is a critical sandbox escape vulnerability in vm2 that allows attackers to bypass sandbox protections and execute arbitrary code on the...
May 15, 2023CVE-2023-29827 is a server-side template injection vulnerability in ejs v3.1.9 that allows attackers to execute arbitrary code if they can control tem...
May 4, 2023This vulnerability in vm2 sandbox allows attackers to escape the sandbox environment and execute arbitrary code on the host system by exploiting impro...
Apr 17, 2023This vulnerability in LangChain's LLMMathChain allows attackers to inject malicious prompts that execute arbitrary Python code via the exec() method. ...
Apr 5, 2023Simple Image Gallery v1.0 contains a remote code execution vulnerability in the username parameter that allows attackers to execute arbitrary code on ...
Mar 16, 2023This vulnerability in UBIKA WAAP Gateway/Cloud allows attackers to bypass authentication by stealing another user's session through blind XPath inject...
Mar 8, 2023An LDAP injection vulnerability in Apache Kerby's LdapIdentityBackend allows attackers to manipulate LDAP queries through user-controlled input. This ...
Feb 20, 2023CVE-2022-34914 is an injection vulnerability in Webswing that allows attackers to manipulate the X-Forwarded-For header to inject arbitrary arguments ...
Jul 8, 2022This CVE describes a Server-Side Template Injection vulnerability in Form.io version 2.0.0 that allows remote code execution when deleting the default...
Jun 2, 2022CVE-2022-25420 is a CRLF injection vulnerability in NTT Resonant's goo blog App Web Application 1.0 that allows attackers to execute arbitrary code vi...
Mar 29, 2022CVE-2022-26205 is a critical remote code execution vulnerability in Marky software that allows attackers to execute arbitrary code by injecting malici...
Mar 27, 2022CVE-2021-44550 is an incorrect access control vulnerability in Stanford CoreNLP's NERServlet that allows unauthenticated remote attackers to bypass au...
Feb 24, 2022This vulnerability in Ibexa DXP allows attackers to perform injection attacks via image filenames. It affects systems running ezsystems/ezpublish-kern...
Feb 18, 2022CVE-2021-43185 is a Host header injection vulnerability in JetBrains YouTrack that allows attackers to manipulate HTTP Host headers to perform web cac...
Nov 9, 2021This vulnerability in neoan3-apps/template allows remote code execution through template injection. Attackers can pass callable values (closures) that...
Nov 8, 2021This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on Apache Storm Nimbus servers by sending specially crafted T...
Oct 25, 2021A path traversal vulnerability in Moxa MXview Network Management software allows attackers to create or overwrite critical files, potentially leading ...
Oct 12, 2021CVE-2021-41862 is a critical remote code execution vulnerability in AviatorScript that allows attackers to execute arbitrary code by crafting maliciou...
Oct 2, 2021CVE-2021-41392 is a critical remote code execution vulnerability in Boost Note desktop application. Attackers can send malicious IPC messages to explo...
Sep 17, 2021CVE-2021-20509 is a CSV injection vulnerability in IBM Maximo Asset Management that allows remote attackers to execute arbitrary commands on affected ...
Aug 12, 2021This vulnerability in Jumpserver allows attackers to create connection tokens through an unprotected API endpoint, which can then be used to access se...
Jul 23, 2021CVE-2018-25016 is a Host Header Injection vulnerability in Greenbone Security Assistant (GSA) and Greenbone OS (GOS) that allows attackers to manipula...
Jun 21, 2021CVE-2021-27730 is an argument injection vulnerability in Accellion FTA that allows attackers to execute arbitrary commands via crafted POST requests t...
Mar 2, 2021This vulnerability allows remote attackers to execute arbitrary shell commands on SaltStack Salt servers via shell injection in the salt-api SSH clien...
Feb 27, 2021CVE-2020-35775 is an LDAP injection vulnerability in CITSmart ITSM software that allows attackers to manipulate LDAP queries through user input. This ...
Feb 15, 2021CVE-2020-15690 is a CRLF injection vulnerability in Nim's asyncftpclient library that allows attackers to inject arbitrary commands into FTP sessions ...
Jan 30, 2021This CVE describes an iframe injection vulnerability in MyNET v.26.06 and earlier that allows remote attackers to execute arbitrary code via the src p...
Dec 22, 2025This vulnerability allows malicious Progressive Web Apps (PWAs) to inject arbitrary code execution commands into desktop configuration files on Linux ...
May 3, 2024This host header injection vulnerability in @perfood/couch-auth allows attackers to send password reset links that redirect to attacker-controlled ser...
Jan 3, 2024This vulnerability affects cryptocurrency wallets implementing GG18 or GG20 threshold signature schemes (TSS). An attacker can extract the full ECDSA ...
Aug 9, 2023This vulnerability allows authenticated attackers to achieve remote code execution on OneDev DevOps platforms by exploiting insecure deserialization i...
Jan 15, 2021CVE-2021-21249 is a post-authentication remote code execution vulnerability in OneDev DevOps platform. It allows authenticated attackers to execute ar...
Jan 15, 2021This CVE describes an AI command injection vulnerability in Microsoft 365 Copilot that allows unauthorized attackers to execute arbitrary commands and...
Jun 11, 2025This vulnerability in PHP's PDO::quote() function for SQLite allows SQL injection when processing overly long user-supplied strings. It affects PHP ap...
Feb 12, 2025This CVE describes multiple command injection vulnerabilities in the Wavlink AC3000 router's nas.cgi add_dir() functionality. An authenticated attacke...
Jan 14, 2025This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers via a crafted HTTP request to the qos.cgi en...
Jan 14, 2025This CVE describes a command injection vulnerability in the Wavlink AC3000 router's wireless.cgi AddMac() function. An authenticated attacker can exec...
Jan 14, 2025This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by sending specially crafted HTTP requests t...
Jan 14, 2025CVE-2021-41128 is a CSV injection vulnerability in Hygeia that allows users to embed malicious formulas in exported CSV files. When these files are op...
Oct 6, 2021This NoSQL injection vulnerability in GROWI wiki software allows attackers to manipulate database queries and access/modify stored data. It affects GR...
Jun 22, 2021This vulnerability allows arbitrary code execution on Grist servers when using the pyodide sandbox flavor with untrusted spreadsheets. Attackers can r...
Jan 22, 2026This vulnerability allows remote attackers to execute arbitrary commands on Wavlink AC3000 routers by sending specially crafted HTTP requests. Attacke...
Jan 14, 2025XWiki Commons HTML sanitizer vulnerability allows attackers without script rights to create phishing forms or embed malicious inputs that could lead t...
Jun 29, 2023About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,158 CVEs classified as CWE-74, with 102 rated critical and 1,268 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free