CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,153)
OrangeHRM versions 5.0 through 5.7 contain a command injection vulnerability in the mail configuration workflow. Unauthenticated attackers can exploit...
Nov 29, 2025The WP All Import WordPress plugin contains a critical remote code execution vulnerability that allows authenticated users with import capabilities (t...
Nov 13, 2025The Elastic Theme Editor WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files through a dy...
Nov 11, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code through the Better Find and R...
Nov 8, 2025A remote code execution vulnerability in iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code through a crafted HTML page targeting t...
Nov 3, 2025This vulnerability allows remote attackers to execute arbitrary code on BusinessNext CRMnext systems through the comments input parameter. It affects ...
Oct 30, 2025This vulnerability allows a low-privileged remote attacker with web management access to inject and execute arbitrary commands as root on affected sys...
Oct 14, 2025CVE-2025-54374 is a one-click remote code execution vulnerability in Eidos Personal Data Management framework. Attackers can embed malicious eidos: UR...
Oct 3, 2025Claude Code versions before 1.0.111 contain a code injection vulnerability that allows arbitrary code execution when users start the application in un...
Oct 3, 2025Dolibarr ERP & CRM version 21.0.1 contains a remote code execution vulnerability in the User module configuration via the computed field parameter. Th...
Oct 1, 2025CVE-2025-57439 is a critical remote code execution vulnerability in Creacast Creabox Manager 4.4.4 where authenticated attackers can inject arbitrary ...
Sep 22, 2025This CVE describes a server-side template injection vulnerability in PPress CMS version 0.0.9 that allows attackers to execute arbitrary code on the s...
Sep 19, 2025This vulnerability allows authenticated attackers with Subscriber-level access or higher to execute arbitrary PHP code on WordPress sites using the WP...
Sep 17, 2025CVE-2025-58176 is a one-click remote code execution vulnerability in Dive MCP Host Desktop Application versions 0.9.0 through 0.9.3. Attackers can exp...
Sep 3, 2025This vulnerability allows remote code execution in Craft CMS when attackers have a compromised security key and can create arbitrary files in the /sto...
Aug 9, 2025This CVE describes a code injection vulnerability in Microsoft Office SharePoint that allows authenticated attackers to execute arbitrary code over th...
Jul 8, 2025This vulnerability allows authenticated users in Bolt CMS 3.7.0 and earlier to achieve remote code execution through a chain of flaws. Attackers can i...
Jul 3, 2025This vulnerability allows authenticated users of Ansible Automation Platform's EDA component to inject malicious Jinja2 templates via Git branch or re...
Jun 30, 2025This vulnerability allows authenticated domain users to execute arbitrary code on Veeam Backup Servers through improper input validation. It affects o...
Jun 19, 2025This vulnerability in XWiki allows users with edit rights on any page (including their own profile) to execute arbitrary code with programming rights ...
Jun 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code on servers running vulnerable...
May 15, 2025This vulnerability allows authenticated attackers to execute arbitrary commands on pfSense firewalls through the OpenVPN widget. Attackers can inject ...
May 14, 2025A remote code execution vulnerability exists in Moodle's Dropbox repository feature, allowing authenticated teachers and managers to execute arbitrary...
Apr 25, 2025This vulnerability allows authenticated attackers to execute arbitrary code on LRQA Nettitude PoshC2 servers by exploiting a flaw in the upload_file f...
Apr 16, 2025PerfreeBlog 4.0.11 contains an arbitrary file upload vulnerability in the attach component that allows regular users to upload malicious files and exe...
Apr 15, 2025This vulnerability allows attackers to execute arbitrary code remotely by injecting malicious parameters into JDBC URLs used by insightsoftware Hive J...
Apr 3, 2025This CVE describes a remote code execution vulnerability in insightsoftware Spark JDBC where attackers can inject malicious parameters into JDBC URLs,...
Apr 3, 2025This vulnerability allows attackers with Item/Configure permission in Jenkins to bypass sandbox protection in the Templating Engine Plugin, enabling a...
Apr 2, 2025This vulnerability in KNIME Business Hub's ingress-nginx component allows authenticated attackers to potentially execute arbitrary code within the Kub...
Mar 26, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to execute arbitrary code on the server through unsafe...
Mar 22, 2025This vulnerability in Dify Tools' Vanna module allows attackers to inject malicious queries through unsanitized user inputs, potentially leading to re...
Mar 20, 2025SuperAGI's latest version contains a critical remote code execution vulnerability in the agent template update API. Attackers can inject malicious cod...
Mar 20, 2025This vulnerability in BerriAI/litellm allows remote code execution by exploiting improper input validation in the 'post_call_rules' configuration. Att...
Mar 20, 2025This vulnerability in kedro 0.19.8 allows remote code execution when users download micro packages via the pull_package() API. Attackers can craft mal...
Mar 20, 2025This vulnerability allows attackers to execute arbitrary code on servers running vulnerable versions of binary-husky/gpt_academic through prompt injec...
Mar 20, 2025This vulnerability allows remote code execution on servers running vulnerable versions of the gpt_academic manim plugin. Attackers can inject maliciou...
Mar 20, 2025Plenti versions up to 0.7.16 are vulnerable to remote code execution via the /postLocal endpoint. Attackers can upload .svelte files with malicious Ja...
Mar 12, 2025GeoVision GV-ASWeb versions 6.1.2.0 and below contain an authenticated remote code execution vulnerability in the Notification Settings feature. An at...
Feb 27, 2025PHPJabbers Restaurant Booking System v3.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code on the server. The vulnera...
Feb 20, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of deep-diver LLM-As-Chatbot. The issue ex...
Feb 6, 2025A WebAssembly code generation bug in Mozilla products could allow attackers to cause crashes and potentially execute arbitrary code. This affects Fire...
Feb 4, 2025CVE-2024-23921 is a critical remote code execution vulnerability in ChargePoint Home Flex charging stations that allows network-adjacent attackers to ...
Jan 31, 2025This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth Low Energy (BLE) without user interaction. It af...
Jan 21, 2025This vulnerability in Android's Bluetooth GATT server allows remote attackers within Bluetooth range to execute arbitrary code without user interactio...
Jan 21, 2025This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Windows Search Service. It affects Windows systems with...
Jan 14, 2025This vulnerability allows authenticated WordPress users with subscriber-level access or higher to upload arbitrary files through the Post Saint plugin...
Jan 7, 2025This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via the formWsc function in the /bin/boa web server. A...
Dec 26, 2024This is a post-authentication code injection vulnerability in Sophos Firewall's User Portal that allows authenticated users to execute arbitrary code ...
Dec 19, 2024A vulnerability in CodeAstro Complaint Management System v1.0 allows remote attackers to escalate privileges through the mess-view.php component. This...
Dec 18, 2024CVE-2024-55661 is a remote code execution vulnerability in Laravel Pulse monitoring tool. Authenticated users with dashboard access can execute arbitr...
Dec 13, 2024About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free