CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,159)
This vulnerability allows a cluster operator with existing access to inject malicious code into Apache Ambari requests, potentially gaining root privi...
Feb 27, 2024A stack overflow vulnerability in Tenda AC21 routers allows attackers to execute arbitrary commands via crafted POST requests to the /goform/openSched...
Feb 21, 2024This vulnerability allows remote code execution through Microsoft Outlook when processing specially crafted email messages. Attackers could execute ar...
Feb 13, 2024CVE-2024-21649 is a code injection vulnerability in vantage6 privacy-enhancing technology platforms that allows authenticated users to execute arbitra...
Jan 30, 2024This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Jan 23, 2024CVE-2024-23750 is a critical code injection vulnerability in MetaGPT that allows attackers with QaEngineer role access to execute arbitrary commands o...
Jan 22, 2024This is a high-severity Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server that allows authenticated attackers to exec...
Jan 16, 2024This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitr...
Jan 16, 2024This vulnerability allows authenticated attackers to execute arbitrary code on HummerRisk systems via a crafted request to the LicenseService componen...
Jan 16, 2024This vulnerability in Scada-LTS allows authenticated attackers with low-level privileges to escalate their permissions, execute arbitrary code, and ac...
Jan 13, 2024This vulnerability allows authenticated attackers to execute arbitrary code on ManageEngine ADSelfService Plus servers due to improper input handling ...
Jan 11, 2024SeaCMS v12.9 contains a remote code execution vulnerability in the /augap/adminip.php component that allows attackers to execute arbitrary code on aff...
Dec 28, 2023The Filr WordPress plugin before version 1.2.3.6 contains a remote code execution vulnerability that allows attackers with Author-level privileges to ...
Dec 4, 2023This vulnerability allows attackers to upload malicious PHP files disguised as images through Statamic's front-end forms and control panel asset uploa...
Nov 14, 2023Subrion CMS 4.2.1 contains a remote command execution vulnerability in the backend that allows authenticated attackers to execute arbitrary commands o...
Nov 3, 2023CVE-2023-46055 is a critical remote code execution vulnerability in ThingNario Photon v1.0 that allows attackers to execute arbitrary code and escalat...
Oct 21, 2023CVE-2023-43661 is a critical remote code execution vulnerability in Cachet status page systems. It allows authenticated users to execute arbitrary cod...
Oct 11, 2023CVE-2023-41450 is a remote code execution vulnerability in phpkobo AjaxNewsTicker v1.0.5 that allows attackers to execute arbitrary code via a crafted...
Sep 28, 2023This is a high-severity remote code execution vulnerability in Bitbucket Data Center and Server that allows authenticated attackers to execute arbitra...
Sep 19, 2023This vulnerability allows authenticated, highly-privileged users to bypass the sandbox environment in Fides webserver API and execute arbitrary code w...
Sep 6, 2023CVE-2022-41763 is a remote code execution vulnerability in NOKIA AMS 9.7.05 where authenticated remote users can inject code via the debugger of the i...
Sep 5, 2023CVE-2023-39059 is a remote code execution vulnerability in Ansible Semaphore where an attacker can execute arbitrary commands via crafted extra variab...
Aug 28, 2023A hidden functionality vulnerability in LOGITEC LAN-WH300N/RE wireless routers allows unauthenticated attackers to execute arbitrary code by sending s...
Aug 18, 2023This vulnerability allows authenticated and authorized Apache NiFi users to configure HTTP URL references for retrieving drivers, enabling custom code...
Jul 29, 2023CVE-2023-35333 is a remote code execution vulnerability in MediaWiki's PandocUpload extension that allows attackers to execute arbitrary code on affec...
Jul 11, 2023This vulnerability allows authenticated attackers to execute arbitrary code on Microsoft SharePoint servers by uploading specially crafted files. It a...
Jul 11, 2023CVE-2023-36859 is a command injection vulnerability in PiiGAB M-Bus SoftwarePack 900S that allows attackers to execute arbitrary commands on affected ...
Jul 6, 2023This vulnerability in Orthanc allows authenticated users with API access to overwrite arbitrary files on the file system. In specific deployment scena...
Jun 29, 2023Bagisto v1.5.1 contains a Server-Side Template Injection (SSTI) vulnerability that allows attackers to execute arbitrary code on the server. This affe...
Jun 28, 2023CVE-2023-32527 is a remote code execution vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 where vulnerable PHP files allow attackers...
Jun 26, 2023This CVE describes a Bean Manipulation vulnerability in SugarCRM's REST API that allows authenticated users to inject custom PHP code through crafted ...
Jun 17, 2023CVE-2023-2943 is a code injection vulnerability in OpenEMR that allows attackers to execute arbitrary code on affected systems. This affects OpenEMR i...
May 27, 2023This CVE describes a code injection vulnerability in TeamPass password manager that allows attackers to execute arbitrary code on affected systems. It...
May 24, 2023This vulnerability allows remote attackers to execute arbitrary code on CraftCMS servers through server-side template injection in the Section paramet...
May 12, 2023CVE-2023-31414 allows arbitrary code execution in Kibana when an attacker with write access to configuration files injects malicious JavaScript payloa...
May 4, 2023This vulnerability allows authenticated attackers to execute arbitrary OS commands through Jinja template injection in InsightCloudSec. It affects sel...
Mar 21, 2023This vulnerability allows authenticated attackers to execute arbitrary Python code through Jinja template injection via an exposed resource.db() metho...
Mar 21, 2023This vulnerability allows authenticated non-administrative users in SAP Solution Manager and ABAP managed systems to exploit a vulnerable interface to...
Mar 14, 2023CVE-2023-24078 is a remote code execution vulnerability in Real Time Logic FuguHub v8.1 and earlier that allows attackers to execute arbitrary code vi...
Feb 17, 2023CVE-2023-0877 is a code injection vulnerability in the Froxlor server management panel that allows authenticated attackers to execute arbitrary code o...
Feb 17, 2023This CVE describes a code injection vulnerability in the Froxlor server management panel that allows attackers to execute arbitrary code on affected s...
Feb 4, 2023CVE-2021-40553 is a remote code execution vulnerability in Piwigo's LocalFiles Editor that allows attackers to execute arbitrary code on affected syst...
Jun 28, 2022CVE-2021-41402 is a remote code execution vulnerability in flatCore-CMS v2.0.8 that allows attackers to execute arbitrary PHP code on affected systems...
Jun 16, 2022This vulnerability in Smarty template engine allows template authors to inject PHP code through malicious {block} names or {include} file names. It af...
May 24, 2022This CVE describes a command injection vulnerability in the manual ping form of Shenzhen Ejoin Information Technology's ACOM508/ACOM516/ACOM532 device...
May 9, 2022Bolt CMS versions up to 4.2 contain a server-side template injection vulnerability in theme rendering functionality. Authenticated attackers can edit ...
Apr 11, 2022CVE-2022-24780 is a critical remote code execution vulnerability in Combodo iTop ITSM software. Authenticated users can inject TWIG template code thro...
Apr 5, 2022This vulnerability allows attackers to inject malicious code into specific parameters of a web application. When legitimate users review history secti...
Mar 10, 2022HotelDruid v3.0.3 contains a remote code execution vulnerability where attackers can inject malicious payloads into the 'name' field when creating new...
Mar 3, 2022CVE-2022-25018 is a critical remote code execution vulnerability in Pluxml CMS that allows attackers to execute arbitrary PHP code by injecting it int...
Mar 1, 2022About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,159 CVEs classified as CWE-94, with 527 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free