CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,153)
CVE-2020-28464 is a critical code injection vulnerability in the djv JSON schema validation library. An attacker who can control the schema file can e...
Jan 4, 2021This is a critical remote code execution vulnerability in zzzphp CMS that allows attackers to execute arbitrary commands on the server through eval in...
Dec 18, 2020CVE-2020-11851 is a critical remote code execution vulnerability in Micro Focus ArcSight Logger affecting all versions before 7.1.1. Attackers can rem...
Nov 17, 2020CVE-2020-7373 is a remote command execution vulnerability in vBulletin forums that allows attackers to execute arbitrary code on affected servers. Thi...
Oct 30, 2020CVE-2020-18185 is a critical remote code execution vulnerability in PluXml 5.7 that allows attackers to execute arbitrary PHP code by modifying the co...
Oct 2, 2020This vulnerability allows remote code injection and privilege escalation in Brocade Fabric OS. Attackers can execute arbitrary code with elevated priv...
Sep 25, 2020This vulnerability allows remote attackers to execute arbitrary C# code on servers running vulnerable versions of Stimulsoft Reports by embedding mali...
Aug 18, 2020This vulnerability allows remote unauthenticated attackers to execute arbitrary commands with SYSTEM privileges on Desigo CC building automation syste...
Aug 14, 2020SuperWebMailer 7.21.0.01526 contains a critical remote code execution vulnerability in the Language parameter of mailingupgrade.php. Unauthenticated a...
Jul 14, 2020CVE-2019-5997 is a critical code injection vulnerability in Video Insight VMS that allows remote attackers to execute arbitrary code on affected syste...
May 20, 2020This vulnerability allows attackers to bypass security controls in Langroid's TableChatAgent and execute arbitrary code through the pandas_eval tool. ...
Feb 4, 2026CVE-2026-22793 is an unsafe option parsing vulnerability in the ECharts Markdown plugin of the 5ire AI assistant that allows arbitrary JavaScript exec...
Jan 21, 2026SiYuan personal knowledge management systems before version 3.5.4 have a stored XSS vulnerability in the dynamic icon feature. Attackers can inject ma...
Jan 19, 2026This vulnerability in the Dive MCP Host Desktop Application allows attackers to install malicious MCP server configurations via crafted deeplinks with...
Jan 16, 2026DeepChat versions before 0.5.3 contain a critical vulnerability where unsafe Mermaid diagram rendering allows arbitrary JavaScript execution. This XSS...
Dec 16, 2025DeepChat versions 0.5.0 and earlier contain a stored XSS vulnerability in the Mermaid diagram renderer that allows attackers to execute arbitrary Java...
Dec 3, 2025CVE-2025-61929 is a critical remote code execution vulnerability in Cherry Studio's custom protocol handler. Attackers can craft malicious cherrystudi...
Oct 10, 2025This vulnerability in AIRI v0.7.2-beta.2 allows attackers to achieve remote code execution through a cross-site scripting (XSS) attack. The XSS vulner...
Sep 11, 2025This vulnerability in DeepChat's Mermaid chart rendering component allows cross-site scripting (XSS) that can lead to remote command execution. Attack...
Sep 9, 2025CVE-2024-41961 is a critical code injection vulnerability in Elektra's live search functionality where authenticated users can inject Ruby code that g...
Aug 1, 2024This vulnerability allows remote code execution on FortiClientLinux installations through code injection. Attackers can execute arbitrary code by tric...
Apr 9, 2024CVE-2023-46242 is a critical vulnerability in XWiki Platform that allows authenticated users with programming privileges to execute arbitrary content ...
Nov 7, 2023This vulnerability in Citrix Secure Access client for Ubuntu allows remote code execution when a user opens a malicious link and accepts prompts. It a...
Jul 11, 2023CVE-2022-1575 is a critical vulnerability in draw.io diagramming software that allows attackers to bypass input sanitization and execute arbitrary cod...
May 5, 2022CVE-2021-39159 is a critical remote code execution vulnerability in BinderHub that allows attackers to execute arbitrary code in the BinderHub context...
Aug 25, 2021CVE-2021-39160 is a critical vulnerability in nbgitpuller, a Jupyter server extension for syncing git repositories. Due to unsanitized input in crafte...
Aug 25, 2021This vulnerability allows authenticated attackers to execute arbitrary code on ZStack IaaS management servers by bypassing Groovy sandbox restrictions...
Aug 17, 2021This vulnerability in OpenMetadata allows remote attackers to execute arbitrary code by exploiting a Spring Expression Language (SpEL) injection flaw....
Mar 15, 2024Baicells EG7035-M11 devices with vulnerable firmware allow remote attackers to execute arbitrary commands with root privileges via HTTP GET requests w...
Mar 1, 2023InvoicePlane 1.7.0 contains a critical Remote Code Execution vulnerability that allows authenticated administrators to execute arbitrary system comman...
Feb 18, 2026This vulnerability in authentik allows authenticated users with specific delegated permissions to execute arbitrary code on the authentik server conta...
Feb 12, 2026This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable Nelio AB Testing plugin. Attackers can inject ...
Jan 22, 2026This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the Hotel Booking Lite plugin. Attackers can inject ma...
Dec 18, 2025pgAdmin versions up to 9.9 running in server mode are vulnerable to remote code execution when processing PLAIN-format database dump files during rest...
Nov 13, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the Paid Videochat Turnkey Site plugin (ppv-live-webca...
Oct 27, 2025This vulnerability allows authenticated administrator users in PluXml CMS to overwrite the minify.php file with arbitrary PHP code via the admin panel...
Oct 17, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable bidorbuy Store Integrator plugin. Attac...
Aug 28, 2025This vulnerability allows privileged OpenBao operators to bypass security restrictions and execute arbitrary code on the underlying host by manipulati...
Aug 9, 2025A privileged Vault operator with write permission to the sys/audit endpoint can execute arbitrary code on the underlying host when Vault is configured...
Aug 1, 2025OpenCTI versions before 6.4.11 contain a critical vulnerability where users with 'manage customizations' capability can execute arbitrary commands on ...
May 5, 2025This vulnerability allows remote authenticated administrators to inject malicious code into Ivanti Connect Secure and Policy Secure systems, leading t...
Feb 11, 2025This vulnerability allows remote attackers to execute arbitrary PHP code on WordPress sites using the WP Ultimate Exporter plugin. Attackers can achie...
Jan 7, 2025CVE-2024-10094 is a code injection vulnerability in Pega Platform that allows attackers to execute arbitrary code on affected systems. This affects al...
Nov 20, 2024This CVE describes a prototype pollution vulnerability in Kibana that allows authenticated attackers with specific permissions to execute arbitrary co...
Aug 13, 2024CVE-2024-37770 is a critical remote command execution vulnerability in 14Finger v1.1 that allows attackers to execute arbitrary system commands via cr...
Jul 10, 2024CVE-2024-38448 is a command injection vulnerability in GNU Global's htags tool that allows arbitrary code execution when processing untrusted database...
Jun 16, 2024This vulnerability allows attackers to launch arbitrary URLs within McAfee Security: Antivirus VPN for Android by exploiting improper deep link valida...
Jun 11, 2024This vulnerability allows authenticated administrators in SailPoint Identity Security Cloud to execute arbitrary code on the host system by using user...
May 15, 2024This vulnerability allows remote attackers to execute arbitrary code on Library System V1.0 installations via improper input validation in the student...
May 6, 2024This SQL injection vulnerability in ITB-GmbH TradePro v9.5 allows remote attackers to execute arbitrary SQL queries through the oordershow component i...
Apr 4, 2024About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free