CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,153
Total CVEs
521
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Moodle 7
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,153)

CVE-2025-66224
8.8

OrangeHRM versions 5.0 through 5.7 contain a command injection vulnerability in the mail configuration workflow. Unauthenticated attackers can exploit...

Nov 29, 2025
CVE-2025-12733
8.8

The WP All Import WordPress plugin contains a critical remote code execution vulnerability that allows authenticated users with import capabilities (t...

Nov 13, 2025
CVE-2025-12637
8.8

The Elastic Theme Editor WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files through a dy...

Nov 11, 2025
CVE-2025-9334
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code through the Better Find and R...

Nov 8, 2025
CVE-2025-60785
8.8

A remote code execution vulnerability in iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code through a crafted HTML page targeting t...

Nov 3, 2025
CVE-2025-61196
8.8

This vulnerability allows remote attackers to execute arbitrary code on BusinessNext CRMnext systems through the comments input parameter. It affects ...

Oct 30, 2025
CVE-2025-41699
8.8

This vulnerability allows a low-privileged remote attacker with web management access to inject and execute arbitrary commands as root on affected sys...

Oct 14, 2025
CVE-2025-54374
8.8

CVE-2025-54374 is a one-click remote code execution vulnerability in Eidos Personal Data Management framework. Attackers can embed malicious eidos: UR...

Oct 3, 2025
CVE-2025-59536
8.8

Claude Code versions before 1.0.111 contain a code injection vulnerability that allows arbitrary code execution when users start the application in un...

Oct 3, 2025
CVE-2025-56588
8.8

Dolibarr ERP & CRM version 21.0.1 contains a remote code execution vulnerability in the User module configuration via the computed field parameter. Th...

Oct 1, 2025
CVE-2025-57439
8.8

CVE-2025-57439 is a critical remote code execution vulnerability in Creacast Creabox Manager 4.4.4 where authenticated attackers can inject arbitrary ...

Sep 22, 2025
CVE-2025-54815
8.8

This CVE describes a server-side template injection vulnerability in PPress CMS version 0.0.9 that allows attackers to execute arbitrary code on the s...

Sep 19, 2025
CVE-2025-10057
8.8

This vulnerability allows authenticated attackers with Subscriber-level access or higher to execute arbitrary PHP code on WordPress sites using the WP...

Sep 17, 2025
CVE-2025-58176
8.8

CVE-2025-58176 is a one-click remote code execution vulnerability in Dive MCP Host Desktop Application versions 0.9.0 through 0.9.3. Attackers can exp...

Sep 3, 2025
CVE-2025-54417
8.8

This vulnerability allows remote code execution in Craft CMS when attackers have a compromised security key and can create arbitrary files in the /sto...

Aug 9, 2025
CVE-2025-49704
KEV EPSS 69.3% 8.8

This CVE describes a code injection vulnerability in Microsoft Office SharePoint that allows authenticated attackers to execute arbitrary code over th...

Jul 8, 2025
CVE-2025-34086
EPSS 50.8% 8.8

This vulnerability allows authenticated users in Bolt CMS 3.7.0 and earlier to achieve remote code execution through a chain of flaws. Attackers can i...

Jul 3, 2025
CVE-2025-49521
8.8

This vulnerability allows authenticated users of Ansible Automation Platform's EDA component to inject malicious Jinja2 templates via Git branch or re...

Jun 30, 2025
CVE-2025-23121
8.8

This vulnerability allows authenticated domain users to execute arbitrary code on Veeam Backup Servers through improper input validation. It affects o...

Jun 19, 2025
CVE-2025-49581
8.8

This vulnerability in XWiki allows users with edit rights on any page (including their own profile) to execute arbitrary code with programming rights ...

Jun 13, 2025
CVE-2025-3053
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code on servers running vulnerable...

May 15, 2025
CVE-2024-54780
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on pfSense firewalls through the OpenVPN widget. Attackers can inject ...

May 14, 2025
CVE-2025-3641
8.8

A remote code execution vulnerability exists in Moodle's Dropbox repository feature, allowing authenticated teachers and managers to execute arbitrary...

Apr 25, 2025
CVE-2024-53303
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on LRQA Nettitude PoshC2 servers by exploiting a flaw in the upload_file f...

Apr 16, 2025
CVE-2025-29281
8.8

PerfreeBlog 4.0.11 contains an arbitrary file upload vulnerability in the attach component that allows regular users to upload malicious files and exe...

Apr 15, 2025
CVE-2024-45199
8.8

This vulnerability allows attackers to execute arbitrary code remotely by injecting malicious parameters into JDBC URLs used by insightsoftware Hive J...

Apr 3, 2025
CVE-2024-45198
8.8

This CVE describes a remote code execution vulnerability in insightsoftware Spark JDBC where attackers can inject malicious parameters into JDBC URLs,...

Apr 3, 2025
CVE-2025-31722
8.8

This vulnerability allows attackers with Item/Configure permission in Jenkins to bypass sandbox protection in the Templating Engine Plugin, enabling a...

Apr 2, 2025
CVE-2025-2787
8.8

This vulnerability in KNIME Business Hub's ingress-nginx component allows authenticated attackers to potentially execute arbitrary code within the Kub...

Mar 26, 2025
CVE-2025-2303
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to execute arbitrary code on the server through unsafe...

Mar 22, 2025
CVE-2025-0185
8.8

This vulnerability in Dify Tools' Vanna module allows attackers to inject malicious queries through unsanitized user inputs, potentially leading to re...

Mar 20, 2025
CVE-2024-9439
8.8

SuperAGI's latest version contains a critical remote code execution vulnerability in the agent template update API. Attackers can inject malicious cod...

Mar 20, 2025
CVE-2024-6825
8.8

This vulnerability in BerriAI/litellm allows remote code execution by exploiting improper input validation in the 'post_call_rules' configuration. Att...

Mar 20, 2025
CVE-2024-12215
8.8

This vulnerability in kedro 0.19.8 allows remote code execution when users download micro packages via the pull_package() API. Attackers can craft mal...

Mar 20, 2025
CVE-2024-10950
8.8

This vulnerability allows attackers to execute arbitrary code on servers running vulnerable versions of binary-husky/gpt_academic through prompt injec...

Mar 20, 2025
CVE-2024-10954
8.8

This vulnerability allows remote code execution on servers running vulnerable versions of the gpt_academic manim plugin. Attackers can inject maliciou...

Mar 20, 2025
CVE-2025-26260
8.8

Plenti versions up to 0.7.16 are vulnerable to remote code execution via the /postLocal endpoint. Attackers can upload .svelte files with malicious Ja...

Mar 12, 2025
CVE-2025-26264
EPSS 10.5% 8.8

GeoVision GV-ASWeb versions 6.1.2.0 and below contain an authenticated remote code execution vulnerability in the Notification Settings feature. An at...

Feb 27, 2025
CVE-2023-51313
8.8

PHPJabbers Restaurant Booking System v3.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code on the server. The vulnera...

Feb 20, 2025
CVE-2024-55241
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of deep-diver LLM-As-Chatbot. The issue ex...

Feb 6, 2025
CVE-2025-1011
8.8

A WebAssembly code generation bug in Mozilla products could allow attackers to cause crashes and potentially execute arbitrary code. This affects Fire...

Feb 4, 2025
CVE-2024-23921
8.8

CVE-2024-23921 is a critical remote code execution vulnerability in ChargePoint Home Flex charging stations that allows network-adjacent attackers to ...

Jan 31, 2025
CVE-2024-43770
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth Low Energy (BLE) without user interaction. It af...

Jan 21, 2025
CVE-2024-43771
8.8

This vulnerability in Android's Bluetooth GATT server allows remote attackers within Bluetooth range to execute arbitrary code without user interactio...

Jan 21, 2025
CVE-2025-21292
8.8

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Windows Search Service. It affects Windows systems with...

Jan 14, 2025
CVE-2024-12471
EPSS 52.4% 8.8

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to upload arbitrary files through the Post Saint plugin...

Jan 7, 2025
CVE-2024-54907
8.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via the formWsc function in the /bin/boa web server. A...

Dec 26, 2024
CVE-2024-12729
8.8

This is a post-authentication code injection vulnerability in Sophos Firewall's User Portal that allows authenticated users to execute arbitrary code ...

Dec 19, 2024
CVE-2024-55505
8.8

A vulnerability in CodeAstro Complaint Management System v1.0 allows remote attackers to escalate privileges through the mess-view.php component. This...

Dec 18, 2024
CVE-2024-55661
8.8

CVE-2024-55661 is a remote code execution vulnerability in Laravel Pulse monitoring tool. Authenticated users with dashboard access can execute arbitr...

Dec 13, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free