CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,161
Total CVEs
102
Critical
1,271
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
219
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,161)

CVE-2025-25477
8.1

A host header injection vulnerability in SysPass 3.2x allows attackers to inject malicious JavaScript from arbitrary domains, which executes in victim...

Feb 28, 2025
CVE-2024-10915
8.1

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected D-Link NAS devices by manipulating the ...

Nov 6, 2024
CVE-2023-46304
8.1

CVE-2023-46304 is a remote code execution vulnerability in Vtiger CRM 7.5.0 where authenticated attackers can write arbitrary PHP code to config.inc.p...

Apr 30, 2024
CVE-2024-28181
8.1

CVE-2024-28181 is an authorization bypass vulnerability in turbo_boost-commands Ruby gem that allows attackers to invoke restricted methods on Command...

Mar 14, 2024
CVE-2024-28114
8.1

CVE-2024-28114 is a Server-Side Template Injection vulnerability in Peering Manager that allows remote code execution. Attackers can execute arbitrary...

Mar 12, 2024
CVE-2024-25625
8.1

This CVE describes a Host Header Injection vulnerability in Pimcore's Admin Classic Bundle that allows attackers to manipulate invitation email links....

Feb 19, 2024
CVE-2024-22319
8.1

This CVE describes a JNDI injection vulnerability in IBM Operational Decision Manager that allows remote attackers to execute arbitrary code by passin...

Feb 2, 2024
CVE-2023-26493
8.1

This CVE describes a command injection vulnerability in Cocos Engine's GitHub Actions workflow that allowed attackers to execute arbitrary commands on...

Mar 27, 2023
CVE-2021-41232
8.1

CVE-2021-41232 is an LDAP injection vulnerability in Thunderdome planning poker tool that allows attackers to manipulate LDAP queries when LDAP authen...

Nov 2, 2021
CVE-2021-39175
8.1

CVE-2021-39175 is a cross-site scripting (XSS) vulnerability in HedgeDoc that allows unauthenticated attackers to inject malicious JavaScript into sli...

Aug 30, 2021
CVE-2021-38290
8.1

This CVE describes a host header injection vulnerability in FUEL CMS versions 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modul...

Aug 9, 2021
CVE-2021-29501
8.1

CVE-2021-29501 is an injection vulnerability in the Ticketer cog for Red Discord Bot that allows Discord users to expose sensitive information through...

May 10, 2021
CVE-2026-24010
8.0

Horilla HRMS versions before 1.5.0 contain a critical file upload vulnerability that allows authenticated users to upload malicious HTML files disguis...

Jan 22, 2026
CVE-2025-3546
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Apr 14, 2025
CVE-2025-3544
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Apr 14, 2025
CVE-2025-3542
8.0

This critical vulnerability allows remote attackers to execute arbitrary commands on affected H3C Magic routers via command injection in the FCGI_Wiza...

Apr 14, 2025
CVE-2025-3540
8.0

This critical vulnerability in H3C Magic routers allows attackers to execute arbitrary commands via a command injection flaw in the wizard configurati...

Apr 13, 2025
CVE-2025-2732
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Mar 25, 2025
CVE-2025-2731
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Mar 25, 2025
CVE-2025-2725
8.0

A critical command injection vulnerability in H3C Magic router series allows attackers to execute arbitrary commands via the /api/login/auth endpoint....

Mar 25, 2025
CVE-2025-2726
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Mar 25, 2025
CVE-2025-2727
8.0

This critical vulnerability in H3C Magic NX30 Pro routers allows attackers on the local network to execute arbitrary commands via a command injection ...

Mar 25, 2025
CVE-2025-2728
8.0

This critical vulnerability in H3C Magic NX30 Pro and Magic NX400 routers allows authenticated attackers on the local network to execute arbitrary com...

Mar 25, 2025
CVE-2025-2729
8.0

This critical vulnerability in H3C Magic routers allows attackers within the local network to execute arbitrary commands via a command injection flaw ...

Mar 25, 2025
CVE-2025-2730
8.0

This critical vulnerability in H3C Magic routers allows authenticated attackers on the local network to execute arbitrary commands via command injecti...

Mar 25, 2025
CVE-2023-28637
8.0

CVE-2023-28637 is a remote code execution vulnerability in DataEase's AWS Redshift data source due to insufficient input sanitization. Attackers can e...

Mar 28, 2023
CVE-2020-23050
8.0

TAO Open Source Assessment Platform v3.3.0 RC02 contains an HTML injection vulnerability in the userFirstName parameter that allows attackers to injec...

Oct 22, 2021
CVE-2021-32647
8.0

This vulnerability allows authenticated attackers to execute arbitrary code on Emissary workflow engine servers by exploiting a class loading mechanis...

Jun 1, 2021
CVE-2024-23333
7.9

CVE-2024-23333 is a path injection vulnerability in LDAP Account Manager (LAM) that allows authenticated attackers to write arbitrary PHP code to web-...

Mar 18, 2024
CVE-2025-7883
7.8

This critical vulnerability in Eluktronics Control Center allows local attackers to execute arbitrary commands through a PowerShell script handler. Th...

Jul 20, 2025
CVE-2025-0396
7.8

This critical vulnerability in exelban stats allows local attackers to execute arbitrary commands through command injection in the XPC Service compone...

Jan 12, 2025
CVE-2024-23268
7.8

This CVE describes a privilege escalation vulnerability in macOS where an application can exploit an injection flaw to gain elevated privileges. It af...

Mar 8, 2024
CVE-2024-23274
7.8

This CVE describes a privilege escalation vulnerability in macOS where an application could exploit an injection flaw to gain elevated privileges. The...

Mar 8, 2024
CVE-2023-48199
7.8

This HTML injection vulnerability in Grocy's API key management component allows attackers to inject arbitrary HTML content into QR code detail popups...

Nov 15, 2023
CVE-2023-46468
7.8

A remote code execution vulnerability in juzawebCMS allows attackers to execute arbitrary code by uploading a malicious file to the custom plugin func...

Oct 28, 2023
CVE-2023-27635
7.8

CVE-2023-27635 is a command injection vulnerability in debmany (part of debian-goodies) that allows attackers to execute arbitrary shell commands via ...

Mar 5, 2023
CVE-2022-20001
7.8

This vulnerability in fish shell versions 3.1.0-3.3.1 allows arbitrary code execution when users navigate to directories containing malicious git conf...

Mar 14, 2022
CVE-2021-38873
7.8

IBM Planning Analytics 2.0 is vulnerable to CSV injection, allowing remote attackers to execute arbitrary commands on the system by exploiting imprope...

Nov 24, 2021
CVE-2021-30777
7.8

This macOS vulnerability allows malicious applications to inject code and gain root privileges through improper input validation. It affects macOS Big...

Sep 8, 2021
CVE-2021-0567
7.8

This vulnerability allows local privilege escalation on Android 11 devices by bypassing font file injection restrictions in RemoteViews.java. Attacker...

Jun 22, 2021
CVE-2026-29053
7.6

Ghost CMS versions 0.7.2 through 6.19.0 contain a vulnerability where malicious themes can execute arbitrary code on the server. This allows attackers...

Mar 5, 2026
CVE-2025-1691
7.6

This CVE describes a control character injection vulnerability in MongoDB Shell (mongosh) where an attacker controlling a MongoDB cluster can craft ma...

Feb 27, 2025
CVE-2024-34697
7.6

A stored HTML injection vulnerability in FreeScout's email reception module allows unauthenticated attackers to inject malicious HTML content into ema...

May 14, 2024
CVE-2023-4818
7.6

PAX A920 payment terminals have a bootloader downgrade vulnerability due to improper version checking. Attackers with physical USB access can install ...

Jan 15, 2024
CVE-2026-22200
EPSS 18.5% 7.5

This vulnerability allows remote attackers to read arbitrary files from the osTicket server filesystem by crafting malicious HTML in ticket content an...

Jan 12, 2026
CVE-2024-49380
7.5

Plenti static site generator versions before 0.7.2 have an arbitrary file write vulnerability in the /postLocal endpoint when serving websites. This a...

Oct 25, 2024
CVE-2024-6331
7.5

This vulnerability allows attackers to read sensitive local files through prompt injection in the Devika AI assistant. It affects systems running Devi...

Aug 4, 2024
CVE-2024-41122
7.5

This vulnerability in Woodpecker CI/CD allows any user to create malicious workflows that can lead to host takeover of the agent executing the workflo...

Jul 19, 2024
CVE-2024-29896
7.5

CVE-2024-29896 is an injection vulnerability in Astro-Shield's automated CSP header generation feature. When enabled with user-controllable content, i...

Mar 28, 2024
CVE-2023-36260
7.5

The Feed Me plugin 4.6.1 for Craft CMS contains a denial of service vulnerability where remote attackers can submit crafted strings to Feed-Me Name an...

Jan 30, 2024

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,161 CVEs classified as CWE-74, with 102 rated critical and 1,271 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free