CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,159
Total CVEs
527
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Moodle 7

All Code Injection CVEs (1,159)

CVE-2023-50379
8.8

This vulnerability allows a cluster operator with existing access to inject malicious code into Apache Ambari requests, potentially gaining root privi...

Feb 27, 2024
CVE-2023-24333
8.8

A stack overflow vulnerability in Tenda AC21 routers allows attackers to execute arbitrary commands via crafted POST requests to the /goform/openSched...

Feb 21, 2024
CVE-2024-21378
8.8

This vulnerability allows remote code execution through Microsoft Outlook when processing specially crafted email messages. Attackers could execute ar...

Feb 13, 2024
CVE-2024-21649
8.8

CVE-2024-21649 is a code injection vulnerability in vantage6 privacy-enhancing technology platforms that allows authenticated users to execute arbitra...

Jan 30, 2024
CVE-2024-0755
8.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Jan 23, 2024
CVE-2024-23750
8.8

CVE-2024-23750 is a critical code injection vulnerability in MetaGPT that allows attackers with QaEngineer role access to execute arbitrary commands o...

Jan 22, 2024
CVE-2024-21673
8.8

This is a high-severity Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server that allows authenticated attackers to exec...

Jan 16, 2024
CVE-2023-22526
8.8

This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitr...

Jan 16, 2024
CVE-2023-43449
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on HummerRisk systems via a crafted request to the LicenseService componen...

Jan 16, 2024
CVE-2023-33472
8.8

This vulnerability in Scada-LTS allows authenticated attackers with low-level privileges to escalate their permissions, execute arbitrary code, and ac...

Jan 13, 2024
CVE-2024-0252
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on ManageEngine ADSelfService Plus servers due to improper input handling ...

Jan 11, 2024
CVE-2023-46987
8.8

SeaCMS v12.9 contains a remote code execution vulnerability in the /augap/adminip.php component that allows attackers to execute arbitrary code on aff...

Dec 28, 2023
CVE-2023-5762
8.8

The Filr WordPress plugin before version 1.2.3.6 contains a remote code execution vulnerability that allows attackers with Author-level privileges to ...

Dec 4, 2023
CVE-2023-48217
8.8

This vulnerability allows attackers to upload malicious PHP files disguised as images through Statamic's front-end forms and control panel asset uploa...

Nov 14, 2023
CVE-2023-46947
8.8

Subrion CMS 4.2.1 contains a remote command execution vulnerability in the backend that allows authenticated attackers to execute arbitrary commands o...

Nov 3, 2023
CVE-2023-46055
8.8

CVE-2023-46055 is a critical remote code execution vulnerability in ThingNario Photon v1.0 that allows attackers to execute arbitrary code and escalat...

Oct 21, 2023
CVE-2023-43661
8.8

CVE-2023-43661 is a critical remote code execution vulnerability in Cachet status page systems. It allows authenticated users to execute arbitrary cod...

Oct 11, 2023
CVE-2023-41450
8.8

CVE-2023-41450 is a remote code execution vulnerability in phpkobo AjaxNewsTicker v1.0.5 that allows attackers to execute arbitrary code via a crafted...

Sep 28, 2023
CVE-2023-22513
8.8

This is a high-severity remote code execution vulnerability in Bitbucket Data Center and Server that allows authenticated attackers to execute arbitra...

Sep 19, 2023
CVE-2023-41319
8.8

This vulnerability allows authenticated, highly-privileged users to bypass the sandbox environment in Fides webserver API and execute arbitrary code w...

Sep 6, 2023
CVE-2022-41763
8.8

CVE-2022-41763 is a remote code execution vulnerability in NOKIA AMS 9.7.05 where authenticated remote users can inject code via the debugger of the i...

Sep 5, 2023
CVE-2023-39059
8.8

CVE-2023-39059 is a remote code execution vulnerability in Ansible Semaphore where an attacker can execute arbitrary commands via crafted extra variab...

Aug 28, 2023
CVE-2023-39445
8.8

A hidden functionality vulnerability in LOGITEC LAN-WH300N/RE wireless routers allows unauthenticated attackers to execute arbitrary code by sending s...

Aug 18, 2023
CVE-2023-36542
8.8

This vulnerability allows authenticated and authorized Apache NiFi users to configure HTTP URL references for retrieving drivers, enabling custom code...

Jul 29, 2023
CVE-2023-35333
8.8

CVE-2023-35333 is a remote code execution vulnerability in MediaWiki's PandocUpload extension that allows attackers to execute arbitrary code on affec...

Jul 11, 2023
CVE-2023-33157
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on Microsoft SharePoint servers by uploading specially crafted files. It a...

Jul 11, 2023
CVE-2023-36859
8.8

CVE-2023-36859 is a command injection vulnerability in PiiGAB M-Bus SoftwarePack 900S that allows attackers to execute arbitrary commands on affected ...

Jul 6, 2023
CVE-2023-33466
8.8

This vulnerability in Orthanc allows authenticated users with API access to overwrite arbitrary files on the file system. In specific deployment scena...

Jun 29, 2023
CVE-2023-33570
8.8

Bagisto v1.5.1 contains a Server-Side Template Injection (SSTI) vulnerability that allows attackers to execute arbitrary code on the server. This affe...

Jun 28, 2023
CVE-2023-32527
8.8

CVE-2023-32527 is a remote code execution vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 where vulnerable PHP files allow attackers...

Jun 26, 2023
CVE-2023-35809
8.8

This CVE describes a Bean Manipulation vulnerability in SugarCRM's REST API that allows authenticated users to inject custom PHP code through crafted ...

Jun 17, 2023
CVE-2023-2943
8.8

CVE-2023-2943 is a code injection vulnerability in OpenEMR that allows attackers to execute arbitrary code on affected systems. This affects OpenEMR i...

May 27, 2023
CVE-2023-2859
8.8

This CVE describes a code injection vulnerability in TeamPass password manager that allows attackers to execute arbitrary code on affected systems. It...

May 24, 2023
CVE-2023-30130
8.8

This vulnerability allows remote attackers to execute arbitrary code on CraftCMS servers through server-side template injection in the Section paramet...

May 12, 2023
CVE-2023-31414
8.8

CVE-2023-31414 allows arbitrary code execution in Kibana when an attacker with write access to configuration files injects malicious JavaScript payloa...

May 4, 2023
CVE-2023-1304
8.8

This vulnerability allows authenticated attackers to execute arbitrary OS commands through Jinja template injection in InsightCloudSec. It affects sel...

Mar 21, 2023
CVE-2023-1306
8.8

This vulnerability allows authenticated attackers to execute arbitrary Python code through Jinja template injection via an exposed resource.db() metho...

Mar 21, 2023
CVE-2023-27893
8.8

This vulnerability allows authenticated non-administrative users in SAP Solution Manager and ABAP managed systems to exploit a vulnerable interface to...

Mar 14, 2023
CVE-2023-24078
8.8

CVE-2023-24078 is a remote code execution vulnerability in Real Time Logic FuguHub v8.1 and earlier that allows attackers to execute arbitrary code vi...

Feb 17, 2023
CVE-2023-0877
8.8

CVE-2023-0877 is a code injection vulnerability in the Froxlor server management panel that allows authenticated attackers to execute arbitrary code o...

Feb 17, 2023
CVE-2023-0671
8.8

This CVE describes a code injection vulnerability in the Froxlor server management panel that allows attackers to execute arbitrary code on affected s...

Feb 4, 2023
CVE-2021-40553
8.8

CVE-2021-40553 is a remote code execution vulnerability in Piwigo's LocalFiles Editor that allows attackers to execute arbitrary code on affected syst...

Jun 28, 2022
CVE-2021-41402
8.8

CVE-2021-41402 is a remote code execution vulnerability in flatCore-CMS v2.0.8 that allows attackers to execute arbitrary PHP code on affected systems...

Jun 16, 2022
CVE-2022-29221
8.8

This vulnerability in Smarty template engine allows template authors to inject PHP code through malicious {block} names or {include} file names. It af...

May 24, 2022
CVE-2022-23332
8.8

This CVE describes a command injection vulnerability in the manual ping form of Shenzhen Ejoin Information Technology's ACOM508/ACOM516/ACOM532 device...

May 9, 2022
CVE-2021-40219
8.8

Bolt CMS versions up to 4.2 contain a server-side template injection vulnerability in theme rendering functionality. Authenticated attackers can edit ...

Apr 11, 2022
CVE-2022-24780
8.8

CVE-2022-24780 is a critical remote code execution vulnerability in Combodo iTop ITSM software. Authenticated users can inject TWIG template code thro...

Apr 5, 2022
CVE-2022-22985
8.8

This vulnerability allows attackers to inject malicious code into specific parameters of a web application. When legitimate users review history secti...

Mar 10, 2022
CVE-2022-22909
8.8

HotelDruid v3.0.3 contains a remote code execution vulnerability where attackers can inject malicious payloads into the 'name' field when creating new...

Mar 3, 2022
CVE-2022-25018
8.8

CVE-2022-25018 is a critical remote code execution vulnerability in Pluxml CMS that allows attackers to execute arbitrary PHP code by injecting it int...

Mar 1, 2022

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,159 CVEs classified as CWE-94, with 527 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free