CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,161)
A host header injection vulnerability in SysPass 3.2x allows attackers to inject malicious JavaScript from arbitrary domains, which executes in victim...
Feb 28, 2025This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected D-Link NAS devices by manipulating the ...
Nov 6, 2024CVE-2023-46304 is a remote code execution vulnerability in Vtiger CRM 7.5.0 where authenticated attackers can write arbitrary PHP code to config.inc.p...
Apr 30, 2024CVE-2024-28181 is an authorization bypass vulnerability in turbo_boost-commands Ruby gem that allows attackers to invoke restricted methods on Command...
Mar 14, 2024CVE-2024-28114 is a Server-Side Template Injection vulnerability in Peering Manager that allows remote code execution. Attackers can execute arbitrary...
Mar 12, 2024This CVE describes a Host Header Injection vulnerability in Pimcore's Admin Classic Bundle that allows attackers to manipulate invitation email links....
Feb 19, 2024This CVE describes a JNDI injection vulnerability in IBM Operational Decision Manager that allows remote attackers to execute arbitrary code by passin...
Feb 2, 2024This CVE describes a command injection vulnerability in Cocos Engine's GitHub Actions workflow that allowed attackers to execute arbitrary commands on...
Mar 27, 2023CVE-2021-41232 is an LDAP injection vulnerability in Thunderdome planning poker tool that allows attackers to manipulate LDAP queries when LDAP authen...
Nov 2, 2021CVE-2021-39175 is a cross-site scripting (XSS) vulnerability in HedgeDoc that allows unauthenticated attackers to inject malicious JavaScript into sli...
Aug 30, 2021This CVE describes a host header injection vulnerability in FUEL CMS versions 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modul...
Aug 9, 2021CVE-2021-29501 is an injection vulnerability in the Ticketer cog for Red Discord Bot that allows Discord users to expose sensitive information through...
May 10, 2021Horilla HRMS versions before 1.5.0 contain a critical file upload vulnerability that allows authenticated users to upload malicious HTML files disguis...
Jan 22, 2026This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Apr 14, 2025This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Apr 14, 2025This critical vulnerability allows remote attackers to execute arbitrary commands on affected H3C Magic routers via command injection in the FCGI_Wiza...
Apr 14, 2025This critical vulnerability in H3C Magic routers allows attackers to execute arbitrary commands via a command injection flaw in the wizard configurati...
Apr 13, 2025This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Mar 25, 2025This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Mar 25, 2025A critical command injection vulnerability in H3C Magic router series allows attackers to execute arbitrary commands via the /api/login/auth endpoint....
Mar 25, 2025This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Mar 25, 2025This critical vulnerability in H3C Magic NX30 Pro routers allows attackers on the local network to execute arbitrary commands via a command injection ...
Mar 25, 2025This critical vulnerability in H3C Magic NX30 Pro and Magic NX400 routers allows authenticated attackers on the local network to execute arbitrary com...
Mar 25, 2025This critical vulnerability in H3C Magic routers allows attackers within the local network to execute arbitrary commands via a command injection flaw ...
Mar 25, 2025This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...
Mar 25, 2025CVE-2023-28637 is a remote code execution vulnerability in DataEase's AWS Redshift data source due to insufficient input sanitization. Attackers can e...
Mar 28, 2023TAO Open Source Assessment Platform v3.3.0 RC02 contains an HTML injection vulnerability in the userFirstName parameter that allows attackers to injec...
Oct 22, 2021This vulnerability allows authenticated attackers to execute arbitrary code on Emissary workflow engine servers by exploiting a class loading mechanis...
Jun 1, 2021CVE-2024-23333 is a path injection vulnerability in LDAP Account Manager (LAM) that allows authenticated attackers to write arbitrary PHP code to web-...
Mar 18, 2024This critical vulnerability in Eluktronics Control Center allows local attackers to execute arbitrary commands through a PowerShell script handler. Th...
Jul 20, 2025This critical vulnerability in exelban stats allows local attackers to execute arbitrary commands through command injection in the XPC Service compone...
Jan 12, 2025This CVE describes a privilege escalation vulnerability in macOS where an application can exploit an injection flaw to gain elevated privileges. It af...
Mar 8, 2024This CVE describes a privilege escalation vulnerability in macOS where an application could exploit an injection flaw to gain elevated privileges. The...
Mar 8, 2024This HTML injection vulnerability in Grocy's API key management component allows attackers to inject arbitrary HTML content into QR code detail popups...
Nov 15, 2023A remote code execution vulnerability in juzawebCMS allows attackers to execute arbitrary code by uploading a malicious file to the custom plugin func...
Oct 28, 2023CVE-2023-27635 is a command injection vulnerability in debmany (part of debian-goodies) that allows attackers to execute arbitrary shell commands via ...
Mar 5, 2023This vulnerability in fish shell versions 3.1.0-3.3.1 allows arbitrary code execution when users navigate to directories containing malicious git conf...
Mar 14, 2022IBM Planning Analytics 2.0 is vulnerable to CSV injection, allowing remote attackers to execute arbitrary commands on the system by exploiting imprope...
Nov 24, 2021This macOS vulnerability allows malicious applications to inject code and gain root privileges through improper input validation. It affects macOS Big...
Sep 8, 2021This vulnerability allows local privilege escalation on Android 11 devices by bypassing font file injection restrictions in RemoteViews.java. Attacker...
Jun 22, 2021Ghost CMS versions 0.7.2 through 6.19.0 contain a vulnerability where malicious themes can execute arbitrary code on the server. This allows attackers...
Mar 5, 2026This CVE describes a control character injection vulnerability in MongoDB Shell (mongosh) where an attacker controlling a MongoDB cluster can craft ma...
Feb 27, 2025A stored HTML injection vulnerability in FreeScout's email reception module allows unauthenticated attackers to inject malicious HTML content into ema...
May 14, 2024PAX A920 payment terminals have a bootloader downgrade vulnerability due to improper version checking. Attackers with physical USB access can install ...
Jan 15, 2024This vulnerability allows remote attackers to read arbitrary files from the osTicket server filesystem by crafting malicious HTML in ticket content an...
Jan 12, 2026Plenti static site generator versions before 0.7.2 have an arbitrary file write vulnerability in the /postLocal endpoint when serving websites. This a...
Oct 25, 2024This vulnerability allows attackers to read sensitive local files through prompt injection in the Devika AI assistant. It affects systems running Devi...
Aug 4, 2024This vulnerability in Woodpecker CI/CD allows any user to create malicious workflows that can lead to host takeover of the agent executing the workflo...
Jul 19, 2024CVE-2024-29896 is an injection vulnerability in Astro-Shield's automated CSP header generation feature. When enabled with user-controllable content, i...
Mar 28, 2024The Feed Me plugin 4.6.1 for Craft CMS contains a denial of service vulnerability where remote attackers can submit crafted strings to Feed-Me Name an...
Jan 30, 2024About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,161 CVEs classified as CWE-74, with 102 rated critical and 1,271 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free