CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,153
Total CVEs
521
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Moodle 7
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,153)

CVE-2020-28464
9.8

CVE-2020-28464 is a critical code injection vulnerability in the djv JSON schema validation library. An attacker who can control the schema file can e...

Jan 4, 2021
CVE-2020-20298
9.8

This is a critical remote code execution vulnerability in zzzphp CMS that allows attackers to execute arbitrary commands on the server through eval in...

Dec 18, 2020
CVE-2020-11851
9.8

CVE-2020-11851 is a critical remote code execution vulnerability in Micro Focus ArcSight Logger affecting all versions before 7.1.1. Attackers can rem...

Nov 17, 2020
CVE-2020-7373
9.8

CVE-2020-7373 is a remote command execution vulnerability in vBulletin forums that allows attackers to execute arbitrary code on affected servers. Thi...

Oct 30, 2020
CVE-2020-18185
9.8

CVE-2020-18185 is a critical remote code execution vulnerability in PluXml 5.7 that allows attackers to execute arbitrary PHP code by modifying the co...

Oct 2, 2020
CVE-2020-15371
9.8

This vulnerability allows remote code injection and privilege escalation in Brocade Fabric OS. Attackers can execute arbitrary code with elevated priv...

Sep 25, 2020
CVE-2020-15865
9.8

This vulnerability allows remote attackers to execute arbitrary C# code on servers running vulnerable versions of Stimulsoft Reports by embedding mali...

Aug 18, 2020
CVE-2020-10055
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary commands with SYSTEM privileges on Desigo CC building automation syste...

Aug 14, 2020
CVE-2020-11546
9.8

SuperWebMailer 7.21.0.01526 contains a critical remote code execution vulnerability in the Language parameter of mailingupgrade.php. Unauthenticated a...

Jul 14, 2020
CVE-2019-5997
9.8

CVE-2019-5997 is a critical code injection vulnerability in Video Insight VMS that allows remote attackers to execute arbitrary code on affected syste...

May 20, 2020
CVE-2026-25481
9.6

This vulnerability allows attackers to bypass security controls in Langroid's TableChatAgent and execute arbitrary code through the pandas_eval tool. ...

Feb 4, 2026
CVE-2026-22793
9.6

CVE-2026-22793 is an unsafe option parsing vulnerability in the ECharts Markdown plugin of the 5ire AI assistant that allows arbitrary JavaScript exec...

Jan 21, 2026
CVE-2026-23852
9.6

SiYuan personal knowledge management systems before version 3.5.4 have a stored XSS vulnerability in the dynamic icon feature. Attackers can inject ma...

Jan 19, 2026
CVE-2026-23523
9.6

This vulnerability in the Dive MCP Host Desktop Application allows attackers to install malicious MCP server configurations via crafted deeplinks with...

Jan 16, 2026
CVE-2025-67744
9.6

DeepChat versions before 0.5.3 contain a critical vulnerability where unsafe Mermaid diagram rendering allows arbitrary JavaScript execution. This XSS...

Dec 16, 2025
CVE-2025-66222
9.6

DeepChat versions 0.5.0 and earlier contain a stored XSS vulnerability in the Mermaid diagram renderer that allows attackers to execute arbitrary Java...

Dec 3, 2025
CVE-2025-61929
9.6

CVE-2025-61929 is a critical remote code execution vulnerability in Cherry Studio's custom protocol handler. Attackers can craft malicious cherrystudi...

Oct 10, 2025
CVE-2025-59053
9.6

This vulnerability in AIRI v0.7.2-beta.2 allows attackers to achieve remote code execution through a cross-site scripting (XSS) attack. The XSS vulner...

Sep 11, 2025
CVE-2025-58768
9.6

This vulnerability in DeepChat's Mermaid chart rendering component allows cross-site scripting (XSS) that can lead to remote command execution. Attack...

Sep 9, 2025
CVE-2024-41961
9.6

CVE-2024-41961 is a critical code injection vulnerability in Elektra's live search functionality where authenticated users can inject Ruby code that g...

Aug 1, 2024
CVE-2023-45590
9.6

This vulnerability allows remote code execution on FortiClientLinux installations through code injection. Attackers can execute arbitrary code by tric...

Apr 9, 2024
CVE-2023-46242
9.6

CVE-2023-46242 is a critical vulnerability in XWiki Platform that allows authenticated users with programming privileges to execute arbitrary content ...

Nov 7, 2023
CVE-2023-24492
9.6

This vulnerability in Citrix Secure Access client for Ubuntu allows remote code execution when a user opens a malicious link and accepts prompts. It a...

Jul 11, 2023
CVE-2022-1575
9.6

CVE-2022-1575 is a critical vulnerability in draw.io diagramming software that allows attackers to bypass input sanitization and execute arbitrary cod...

May 5, 2022
CVE-2021-39159
9.6

CVE-2021-39159 is a critical remote code execution vulnerability in BinderHub that allows attackers to execute arbitrary code in the BinderHub context...

Aug 25, 2021
CVE-2021-39160
9.6

CVE-2021-39160 is a critical vulnerability in nbgitpuller, a Jupyter server extension for syncing git repositories. Due to unsanitized input in crafte...

Aug 25, 2021
CVE-2021-32829
9.6

This vulnerability allows authenticated attackers to execute arbitrary code on ZStack IaaS management servers by bypassing Groovy sandbox restrictions...

Aug 17, 2021
CVE-2024-28253
9.4

This vulnerability in OpenMetadata allows remote attackers to execute arbitrary code by exploiting a Spring Expression Language (SpEL) injection flaw....

Mar 15, 2024
CVE-2023-1097
9.3

Baicells EG7035-M11 devices with vulnerable firmware allow remote attackers to execute arbitrary commands with root privileges via HTTP GET requests w...

Mar 1, 2023
CVE-2026-25548
9.1

InvoicePlane 1.7.0 contains a critical Remote Code Execution vulnerability that allows authenticated administrators to execute arbitrary system comman...

Feb 18, 2026
CVE-2026-25227
9.1

This vulnerability in authentik allows authenticated users with specific delegated permissions to execute arbitrary code on the authentik server conta...

Feb 12, 2026
CVE-2025-67944
9.1

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable Nelio AB Testing plugin. Attackers can inject ...

Jan 22, 2026
CVE-2025-66078
9.1

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the Hotel Booking Lite plugin. Attackers can inject ma...

Dec 18, 2025
CVE-2025-12762
9.1

pgAdmin versions up to 9.9 running in server mode are vulnerable to remote code execution when processing PLAIN-format database dump files during rest...

Nov 13, 2025
CVE-2025-62959
9.1

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the Paid Videochat Turnkey Site plugin (ppv-live-webca...

Oct 27, 2025
CVE-2025-57567
9.1

This vulnerability allows authenticated administrator users in PluXml CMS to overwrite the minify.php file with arbitrary PHP code via the admin panel...

Oct 17, 2025
CVE-2025-48100
9.1

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable bidorbuy Store Integrator plugin. Attac...

Aug 28, 2025
CVE-2025-54997
9.1

This vulnerability allows privileged OpenBao operators to bypass security restrictions and execute arbitrary code on the underlying host by manipulati...

Aug 9, 2025
CVE-2025-6000
9.1

A privileged Vault operator with write permission to the sys/audit endpoint can execute arbitrary code on the underlying host when Vault is configured...

Aug 1, 2025
CVE-2025-24977
9.1

OpenCTI versions before 6.4.11 contain a critical vulnerability where users with 'manage customizations' capability can execute arbitrary commands on ...

May 5, 2025
CVE-2024-10644
EPSS 24.7% 9.1

This vulnerability allows remote authenticated administrators to inject malicious code into Ivanti Connect Secure and Policy Secure systems, leading t...

Feb 11, 2025
CVE-2024-56278
EPSS 42.7% 9.1

This vulnerability allows remote attackers to execute arbitrary PHP code on WordPress sites using the WP Ultimate Exporter plugin. Attackers can achie...

Jan 7, 2025
CVE-2024-10094
9.1

CVE-2024-10094 is a code injection vulnerability in Pega Platform that allows attackers to execute arbitrary code on affected systems. This affects al...

Nov 20, 2024
CVE-2024-37287
9.1

This CVE describes a prototype pollution vulnerability in Kibana that allows authenticated attackers with specific permissions to execute arbitrary co...

Aug 13, 2024
CVE-2024-37770
9.1

CVE-2024-37770 is a critical remote command execution vulnerability in 14Finger v1.1 that allows attackers to execute arbitrary system commands via cr...

Jul 10, 2024
CVE-2024-38448
9.1

CVE-2024-38448 is a command injection vulnerability in GNU Global's htags tool that allows arbitrary code execution when processing untrusted database...

Jun 16, 2024
CVE-2024-34405
9.1

This vulnerability allows attackers to launch arbitrary URLs within McAfee Security: Antivirus VPN for Android by exploiting improper deep link valida...

Jun 11, 2024
CVE-2024-3319
9.1

This vulnerability allows authenticated administrators in SailPoint Identity Security Cloud to execute arbitrary code on the host system by using user...

May 15, 2024
CVE-2024-33294
9.1

This vulnerability allows remote attackers to execute arbitrary code on Library System V1.0 installations via improper input validation in the student...

May 6, 2024
CVE-2023-36645
9.1

This SQL injection vulnerability in ITB-GmbH TradePro v9.5 allows remote attackers to execute arbitrary SQL queries through the oordershow component i...

Apr 4, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free