CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,158
Total CVEs
526
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Moodle 7
10 Craftcms 7

All Code Injection CVEs (1,158)

CVE-2024-12471
EPSS 52.4% 8.8

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to upload arbitrary files through the Post Saint plugin...

Jan 7, 2025
CVE-2024-54907
8.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via the formWsc function in the /bin/boa web server. A...

Dec 26, 2024
CVE-2024-12729
8.8

This is a post-authentication code injection vulnerability in Sophos Firewall's User Portal that allows authenticated users to execute arbitrary code ...

Dec 19, 2024
CVE-2024-55505
8.8

A vulnerability in CodeAstro Complaint Management System v1.0 allows remote attackers to escalate privileges through the mess-view.php component. This...

Dec 18, 2024
CVE-2024-55661
8.8

CVE-2024-55661 is a remote code execution vulnerability in Laravel Pulse monitoring tool. Authenticated users with dashboard access can execute arbitr...

Dec 13, 2024
CVE-2024-11697
8.8

This vulnerability allows attackers to bypass the 'Open Executable File?' confirmation dialog in Firefox and Thunderbird by tricking users with keypre...

Nov 26, 2024
CVE-2024-50808
8.8

SeaCms 13.1 contains a code injection vulnerability in the admin notification module that allows authenticated backend users to execute arbitrary code...

Nov 8, 2024
CVE-2024-46960
8.8

This vulnerability allows attackers to execute arbitrary JavaScript code in the HD Video Downloader All Format Android app through a vulnerable compon...

Nov 7, 2024
CVE-2024-51329
8.8

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to manipulate password reset links to steal reset tokens. This affects all u...

Nov 4, 2024
CVE-2024-48655
8.8

CVE-2024-48655 is a server-side JavaScript code injection vulnerability in Total.js CMS v1.0 that allows remote attackers to execute arbitrary code vi...

Oct 25, 2024
CVE-2024-10131
8.8

This CVE describes a remote code execution vulnerability in the add_llm function of infiniflow/ragflow version 0.11.0. Attackers can exploit user-cont...

Oct 19, 2024
CVE-2024-44414
8.8

This critical vulnerability in FBM_292W-21.03.10V allows remote attackers to execute arbitrary commands on affected devices by manipulating the path p...

Oct 11, 2024
CVE-2024-6983
8.8

CVE-2024-6983 is a critical remote code execution vulnerability in mudler/localai version 2.17.1 that allows attackers to upload malicious binary file...

Sep 27, 2024
CVE-2024-46489
8.8

A remote command execution vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands on affected systems by sending specially cra...

Sep 25, 2024
CVE-2024-8268
8.8

The Frontend Dashboard WordPress plugin allows authenticated attackers with subscriber-level access or higher to execute arbitrary PHP functions throu...

Sep 10, 2024
CVE-2024-42902
8.8

This vulnerability allows attackers to execute arbitrary code on LimeSurvey servers by injecting malicious payloads into the lng parameter of the js_l...

Sep 3, 2024
CVE-2023-26322
8.8

This vulnerability allows attackers to bypass verification logic in XiaomiGetApps, potentially leading to remote code execution. Users of Xiaomi devic...

Aug 28, 2024
CVE-2023-26324
8.8

This vulnerability allows attackers to bypass verification logic in XiaomiGetApps, potentially leading to remote code execution on affected devices. U...

Aug 28, 2024
CVE-2024-7656
8.8

The Image Hotspot by DevVN WordPress plugin is vulnerable to PHP object injection through deserialization of untrusted input. This allows authenticate...

Aug 24, 2024
CVE-2024-42756
8.8

This vulnerability allows remote attackers to execute arbitrary code on Netgear DGN1000WW routers via the Diagnostics page. It affects users running v...

Aug 23, 2024
CVE-2024-5466
8.8

This vulnerability allows authenticated attackers to execute arbitrary code remotely on ManageEngine OpManager and Remote Monitoring and Management sy...

Aug 23, 2024
CVE-2024-42599
8.8

SeaCMS 13.0 contains a remote code execution vulnerability in admin_files.php where authenticated attackers can bypass file editing restrictions to wr...

Aug 22, 2024
CVE-2024-5651
8.8

This vulnerability allows remote code execution in the Fence Agents Remediation operator by injecting arbitrary commands into --ssh-path/--telnet-path...

Aug 12, 2024
CVE-2024-6891
8.8

Attackers with valid credentials can execute arbitrary Python code during login by exploiting improper input validation. This affects systems using vu...

Aug 8, 2024
CVE-2024-34344
8.8

This vulnerability allows server-side JavaScript execution through insufficient path validation in Nuxt's test component wrapper. Attackers can achiev...

Aug 5, 2024
CVE-2024-6726
8.8

This vulnerability in Delphix Engine allows remote attackers to execute arbitrary code on affected systems. The flaw exists in versions before 25.0.0....

Jul 29, 2024
CVE-2024-41667
8.8

CVE-2024-41667 is a template injection vulnerability in OpenAM's OAuth2 provider settings that allows attackers to execute arbitrary code on affected ...

Jul 24, 2024
CVE-2024-29178
8.8

This CVE describes a template injection vulnerability in Apache software versions before 2.1.4 that allows authenticated users to execute arbitrary co...

Jul 18, 2024
CVE-2024-29014
8.8

This vulnerability in SonicWall SMA100 NetExtender Windows client allows an attacker to execute arbitrary code when processing an EPC Client update. I...

Jul 18, 2024
CVE-2024-39877
8.8

This vulnerability allows authenticated DAG authors in Apache Airflow to craft malicious doc_md parameters that can execute arbitrary code in the sche...

Jul 17, 2024
CVE-2024-6345
8.8

This vulnerability in setuptools allows remote code execution when user-controlled URLs are processed by the package_index module. Attackers can injec...

Jul 15, 2024
CVE-2024-40522
8.8

SeaCMS 12.9 contains a remote code execution vulnerability in phomebak.php where unfiltered variable names are written into PHP files. Authenticated a...

Jul 12, 2024
CVE-2024-40552
8.8

PublicCMS v4.0.202302.e contains a remote code execution vulnerability in the ScriptComponent.java file via the cmdarray parameter. This allows attack...

Jul 12, 2024
CVE-2024-33871
8.8

This vulnerability in Ghostscript allows arbitrary code execution by loading a malicious dynamic library specified in a crafted PostScript document. I...

Jul 3, 2024
CVE-2024-37821
8.8

This vulnerability allows attackers to upload malicious .SQL files through the Upload Template function in Dolibarr ERP CRM, potentially leading to ar...

Jun 18, 2024
CVE-2024-5834
8.8

This vulnerability in Google Chrome's Dawn WebGPU implementation allows remote attackers to execute arbitrary code by tricking users into visiting a m...

Jun 11, 2024
CVE-2023-6743
8.8

This vulnerability allows authenticated WordPress users with contributor-level access or higher to execute arbitrary code on the server through the Un...

May 29, 2024
CVE-2024-21683
8.8

This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitr...

May 21, 2024
CVE-2024-32352
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on TOTOLINK X5000R routers by manipulating the ipsecL2tpEnable paramet...

May 14, 2024
CVE-2024-32350
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on TOTOLINK X5000R routers by exploiting improper input validation in ...

May 14, 2024
CVE-2024-33430
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening a specially crafted .wav audio file. It affects ph...

May 1, 2024
CVE-2023-50260
8.8

This vulnerability in Wazuh's host_deny script allows attackers to inject arbitrary commands into the /etc/hosts.deny file, leading to arbitrary comma...

Apr 19, 2024
CVE-2024-26362
8.8

An HTML injection vulnerability in Enpass Password Manager Desktop Client allows attackers to execute arbitrary HTML code by creating specially crafte...

Apr 10, 2024
CVE-2024-30565
8.8

SeaCMS version 12.9 contains a vulnerability in admin/notify.php that allows remote attackers to execute arbitrary code. This is a code injection vuln...

Apr 4, 2024
CVE-2024-29477
8.8

This vulnerability in Dolibarr ERP CRM allows attackers with adjacent network access to execute arbitrary code during the installation process due to ...

Apr 3, 2024
CVE-2024-28118
8.8

This vulnerability in Grav CMS allows administrative users to bypass SSTI mitigations and execute arbitrary code through Twig template processing. Att...

Mar 21, 2024
CVE-2024-28116
8.8

Grav CMS versions before 1.7.45 contain a Server-Side Template Injection vulnerability that allows authenticated users with editor permissions to exec...

Mar 21, 2024
CVE-2024-28848
8.8

This vulnerability allows authenticated non-admin users in OpenMetadata to execute arbitrary system commands via SpEL expression injection. Attackers ...

Mar 15, 2024
CVE-2024-27756
8.8

CVE-2024-27756 is a CSV injection vulnerability in GLPI that allows attackers to embed malicious formulas in asset titles. When exported to CSV and op...

Mar 15, 2024
CVE-2023-50379
8.8

This vulnerability allows a cluster operator with existing access to inject malicious code into Apache Ambari requests, potentially gaining root privi...

Feb 27, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,158 CVEs classified as CWE-94, with 526 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free