CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,153
Total CVEs
521
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Moodle 7
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,153)

CVE-2024-22131
9.1

This vulnerability in SAP ABA allows authenticated users with remote execution authorization to exploit a vulnerable interface, enabling them to invok...

Feb 13, 2024
CVE-2023-51420
9.1

This vulnerability allows remote code execution through improper input validation in Verge3D Publishing and E-Commerce WordPress plugin. Attackers can...

Dec 29, 2023
CVE-2023-40606
9.1

This CVE describes a code injection vulnerability in the Kanban Boards for WordPress plugin that allows attackers to execute arbitrary code on affecte...

Dec 29, 2023
CVE-2023-44382
9.1

October CMS has a critical vulnerability where authenticated backend users with specific editor permissions can bypass the Twig sandbox and execute ar...

Dec 1, 2023
CVE-2023-23551
9.1

Control By Web X-600M devices are vulnerable to Lua code injection, allowing remote attackers to execute arbitrary code on affected devices. This affe...

Feb 13, 2023
CVE-2021-46063
9.1

MCMS v5.2.5 contains a Server-Side Template Injection (SSTI) vulnerability in the Template Management module that allows attackers to execute arbitrar...

Feb 18, 2022
CVE-2021-44521
9.1

This vulnerability allows authenticated attackers with permissions to create user-defined functions in Apache Cassandra to execute arbitrary code on t...

Feb 11, 2022
CVE-2021-37079
9.1

This vulnerability in Huawei smartphones allows attackers with system_app permission to delete arbitrary files due to improper input validation. It af...

Dec 7, 2021
CVE-2026-27493
9.0

This CVE describes a second-order expression injection vulnerability in n8n's Form nodes that could allow unauthenticated attackers to inject and eval...

Feb 25, 2026
CVE-2025-68015
9.0

This CVE describes a code injection vulnerability in the Vollstart Event Tickets with Ticket Scanner WordPress plugin that allows attackers to execute...

Jan 22, 2026
CVE-2025-58766
9.0

This critical vulnerability in Dyad v0.19.0 and earlier allows attackers to execute arbitrary code on users' systems by crafting malicious web content...

Sep 17, 2025
CVE-2025-27407
9.0

This vulnerability in graphql-ruby allows remote code execution when loading malicious schema definitions via GraphQL introspection. Systems that load...

Mar 12, 2025
CVE-2025-23061
EPSS 64.8% 9.0

Mongoose before version 8.9.5 contains a search injection vulnerability when using nested $where filters with populate() match operations. This allows...

Jan 15, 2025
CVE-2024-49375
9.0

CVE-2024-49375 is a critical remote code execution vulnerability in Rasa, an open-source machine learning framework for conversational AI. Attackers c...

Jan 14, 2025
CVE-2024-37899
9.0

This vulnerability in XWiki Platform allows privilege escalation through improper access control. When an administrator disables a user account, the u...

Jun 20, 2024
CVE-2024-22144
9.0

This vulnerability allows unauthenticated attackers to perform predictable nonce brute-force attacks leading to remote code execution (RCE) in the Got...

Apr 25, 2024
CVE-2023-39157
9.0

CVE-2023-39157 is an authenticated remote code execution vulnerability in the Crocoblock JetElements for Elementor WordPress plugin. Attackers with co...

Dec 31, 2023
CVE-2023-45849
9.0

This vulnerability allows attackers to execute arbitrary code with elevated privileges on Helix Core servers. It affects all Helix Core installations ...

Nov 8, 2023
CVE-2022-23631
9.0

CVE-2022-23631 is a critical remote code execution vulnerability in superjson versions before 1.8.1. It allows attackers to execute arbitrary code on ...

Feb 9, 2022
CVE-2022-21686
9.0

This vulnerability allows attackers to inject Twig template code into the PrestaShop back office when using legacy layouts. Successful exploitation co...

Jan 26, 2022
CVE-2020-15150
9.0

This vulnerability in the Paginator Elixir/Hex package allows remote attackers to execute arbitrary code by manipulating input parameters to the pagin...

Sep 1, 2020
CVE-2023-45673
8.9

This vulnerability in Joplin note-taking application allows remote code execution when users click on links within PDFs attached to untrusted notes. A...

Jun 21, 2024
CVE-2026-21853
8.8

This CVE describes a one-click remote code execution vulnerability in AFFiNE workspace software. Attackers can exploit it by tricking users into visit...

Mar 2, 2026
CVE-2026-3132
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code on servers running the Master...

Mar 2, 2026
CVE-2026-27952
8.8

This CVE describes a Python sandbox escape vulnerability in Agenta's API server that allows authenticated users to bypass RestrictedPython sandboxing ...

Feb 26, 2026
CVE-2026-27498
8.8

This vulnerability allows authenticated users with workflow creation/modification permissions in n8n to achieve remote code execution by chaining file...

Feb 25, 2026
CVE-2026-26056
8.8

This vulnerability allows users with create/update permissions in Yoke's Air Traffic Controller to execute arbitrary WASM code by injecting malicious ...

Feb 12, 2026
CVE-2026-0969
8.8

CVE-2026-0969 allows remote attackers to execute arbitrary code on servers using next-mdx-remote when processing untrusted MDX content. This occurs be...

Feb 12, 2026
CVE-2026-1560
8.8

This vulnerability in the Lazy Blocks WordPress plugin allows authenticated attackers with Contributor-level access or higher to execute arbitrary cod...

Feb 11, 2026
CVE-2026-21537
8.8

A code injection vulnerability in Microsoft Defender for Linux allows attackers on adjacent networks to execute arbitrary code without authorization. ...

Feb 10, 2026
CVE-2026-25807
8.8

CVE-2026-25807 is a critical vulnerability in ZAI Shell's P2P terminal sharing feature that allows unauthenticated remote attackers to execute arbitra...

Feb 9, 2026
CVE-2026-24780
8.8

This vulnerability allows authenticated users in AutoGPT Platform to execute disabled BlockInstallationBlock components, which write arbitrary Python ...

Jan 29, 2026
CVE-2026-24747
8.8

A vulnerability in PyTorch's `weights_only` unpickler allows attackers to craft malicious checkpoint files (.pth) that, when loaded, can corrupt memor...

Jan 27, 2026
CVE-2025-67847
8.8

This vulnerability allows attackers with access to Moodle's restore interface to execute arbitrary code on the server due to insufficient input valida...

Jan 23, 2026
CVE-2026-0766
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary Python code on Open WebUI installations via command injection in the loa...

Jan 23, 2026
CVE-2026-22807
8.8

This vulnerability allows arbitrary code execution on vLLM servers during model loading. Attackers who can influence the model repository or path (loc...

Jan 21, 2026
CVE-2021-47770
8.8

OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to upload malicious hardware con...

Jan 21, 2026
CVE-2026-23742
8.8

CVE-2026-23742 allows attackers with ability to create Lua filters in Skipper to read arbitrary files accessible to the Skipper process, potentially e...

Jan 16, 2026
CVE-2025-41717
8.8

An unauthenticated remote attacker can trick a high-privileged user into uploading malicious configuration files via the config-upload endpoint, leadi...

Jan 13, 2026
CVE-2026-22771
8.8

Envoy Gateway versions before 1.5.7 and 1.6.2 contain a vulnerability where Lua scripts in EnvoyExtensionPolicy can leak proxy credentials. Attackers ...

Jan 12, 2026
CVE-2025-55204
8.8

Muffon music streaming client versions before 2.3.0 have a one-click remote code execution vulnerability via specially crafted muffon:// links. When v...

Jan 5, 2026
CVE-2025-65817
8.8

LSC Smart Connect Indoor IP Camera version 1.4.13 contains a remote code execution vulnerability in the start_app.sh script. Attackers can execute arb...

Dec 22, 2025
CVE-2023-53888
8.8

CVE-2023-53888 is a remote code execution vulnerability in Zomplog 3.9 that allows authenticated attackers to upload malicious JavaScript files, renam...

Dec 15, 2025
CVE-2025-66437
8.8

This CVE describes a Server-Side Template Injection (SSTI) vulnerability in Frappe ERPNext that allows authenticated attackers with Address Template p...

Dec 15, 2025
CVE-2025-66438
8.8

This Server-Side Template Injection (SSTI) vulnerability in Frappe ERPNext allows authenticated attackers with Print Format creation/modification perm...

Dec 15, 2025
CVE-2025-66434
8.8

An authenticated attacker with Dunning Type configuration access can exploit this Server-Side Template Injection vulnerability in Frappe ERPNext to ex...

Dec 15, 2025
CVE-2025-66457
8.8

CVE-2025-66457 allows arbitrary code execution in Elysia framework when dynamic cookies are enabled. Attackers can inject malicious cookie configurati...

Dec 9, 2025
CVE-2025-65271
8.8

This CVE describes a client-side template injection vulnerability in Azuriom CMS that allows low-privileged users to execute arbitrary template code w...

Dec 8, 2025
CVE-2025-66299
8.8

Grav CMS versions before 1.8.0-beta.27 contain a Server-Side Template Injection vulnerability that allows authenticated users with editor permissions ...

Dec 1, 2025
CVE-2025-66294
EPSS 38.3% 8.8

This Server-Side Template Injection (SSTI) vulnerability in Grav allows authenticated users with editor permissions to execute arbitrary commands on t...

Dec 1, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free