CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,161
Total CVEs
529
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 10
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Google 7
9 Moodle 7
10 Craftcms 7

All Code Injection CVEs (1,161)

CVE-2022-22909
8.8

HotelDruid v3.0.3 contains a remote code execution vulnerability where attackers can inject malicious payloads into the 'name' field when creating new...

Mar 3, 2022
CVE-2022-25018
8.8

CVE-2022-25018 is a critical remote code execution vulnerability in Pluxml CMS that allows attackers to execute arbitrary PHP code by injecting it int...

Mar 1, 2022
CVE-2021-46114
8.8

CVE-2021-46114 is a remote code execution vulnerability in JPress v4.2.0 that allows authenticated attackers with admin panel access to inject malicio...

Jan 26, 2022
CVE-2021-43269
8.8

This vulnerability allows attackers to execute arbitrary code by injecting malicious JavaScript through proxy configuration in Code42 applications. It...

Jan 20, 2022
CVE-2021-45806
8.8

CVE-2021-45806 is a code injection vulnerability in JPress v4.2.0 admin panel that allows authenticated attackers to modify templates and execute mali...

Jan 13, 2022
CVE-2021-42309
8.8

CVE-2021-42309 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code o...

Dec 15, 2021
CVE-2021-40348
8.8

CVE-2021-40348 is a code injection vulnerability in Spacewalk 2.10 and Uyuni 2021.08 that allows attackers to append arbitrary code to root-owned file...

Nov 1, 2021
CVE-2021-24546
8.8

This vulnerability allows users with contributor-level access in WordPress to execute arbitrary PHP code through the Gutenberg Block Editor Toolkit pl...

Oct 11, 2021
CVE-2020-21650
8.8

CVE-2020-21650 is a remote code execution vulnerability in Myucms v2.2.1 that allows attackers to execute arbitrary code on affected systems via the a...

Oct 6, 2021
CVE-2020-20124
8.8

CVE-2020-20124 is a remote code execution vulnerability in Wuzhi CMS v4.1.0 that allows attackers to execute arbitrary code on affected systems throug...

Sep 28, 2021
CVE-2021-22952
8.8

This vulnerability allows an attacker who has already compromised a network to take control of UniFi Talk devices that haven't been adopted yet. It af...

Sep 23, 2021
CVE-2020-23219
8.8

Monstra CMS 3.0.4 contains a code injection vulnerability in the 'Edit Snippet' module that allows authenticated attackers to execute arbitrary code o...

Jul 1, 2021
CVE-2020-22201
8.8

CVE-2020-22201 is a remote code execution vulnerability in phpCMS 2008 sp4 that allows attackers to execute arbitrary PHP commands via the pagesize pa...

Jun 16, 2021
CVE-2021-32673
8.8

CVE-2021-32673 is a critical command injection vulnerability in reg-keygen-git-hash-plugin that allows remote attackers to execute arbitrary commands ...

Jun 8, 2021
CVE-2021-32924
8.8

This vulnerability allows authenticated moderators in Invision Community (IPS Community Suite) to execute arbitrary PHP code via eval injection in the...

Jun 1, 2021
CVE-2021-32621
8.8

This vulnerability allows authenticated users without Script or Programming rights to execute privileged scripts by editing gadget titles in XWiki Pla...

May 28, 2021
CVE-2021-22894
8.8

This is a critical buffer overflow vulnerability in Pulse Connect Secure VPN appliances that allows remote authenticated attackers to execute arbitrar...

May 27, 2021
CVE-2021-31181
8.8

CVE-2021-31181 is a remote code execution vulnerability in Microsoft SharePoint Server that allows attackers to execute arbitrary code on affected sys...

May 11, 2021
CVE-2021-1362
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on Cisco Unified Communications products via a...

Apr 8, 2021
CVE-2021-27438
8.8

CVE-2021-27438 is a hard-coded password vulnerability in Reason DR60 devices that allows attackers to bypass authentication mechanisms. This affects a...

Mar 25, 2021
CVE-2021-27230
8.8

This vulnerability allows authenticated users with translation permissions to inject arbitrary PHP code into language files in ExpressionEngine CMS. S...

Mar 15, 2021
CVE-2021-21480
8.8

CVE-2021-21480 is a critical remote code execution vulnerability in SAP MII's Self Service Composition Environment (SSCE). Attackers with developer ac...

Mar 9, 2021
CVE-2006-3730
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected systems through an integer overflow in Internet Explorer's WebViewFol...

Jul 21, 2006
CVE-2025-29807
8.7

This vulnerability allows an authorized attacker to execute arbitrary code on Microsoft Dataverse servers by exploiting insecure deserialization of un...

Mar 21, 2025
CVE-2024-53561
8.7

A remote code execution vulnerability in Arcadyan Meteor 2 CPE FG360 firmware allows attackers to execute arbitrary code on affected devices via speci...

Jan 14, 2025
CVE-2021-36800
8.7

CVE-2021-36800 is a code injection vulnerability in Akaunting accounting software that allows remote attackers to execute arbitrary PHP code by sendin...

Aug 4, 2021
CVE-2025-61732
8.6

This vulnerability in Go's cgo tool allows attackers to smuggle malicious code into compiled binaries by exploiting differences in how Go and C/C++ co...

Feb 5, 2026
CVE-2024-57609
8.6

A code injection vulnerability in Pygwalker's login redirection function allows attackers to execute arbitrary code and access sensitive information b...

Feb 6, 2025
CVE-2024-23278
8.6

This vulnerability allows a malicious app to escape its sandbox restrictions on Apple operating systems, potentially accessing system resources or oth...

Mar 8, 2024
CVE-2024-25713
8.6

CVE-2024-25713 is a double-free vulnerability in yyjson library versions through 0.8.0 that can lead to memory corruption and potentially remote code ...

Feb 29, 2024
CVE-2023-30990
8.6

This vulnerability allows remote attackers to execute arbitrary CL commands as the QUSER account on IBM i systems by exploiting the DDM architecture. ...

Jul 4, 2023
CVE-2025-53547
8.5

This vulnerability in Helm allows local code execution when updating dependencies if a malicious Chart.yaml file exists and Chart.lock is symlinked to...

Jul 8, 2025
CVE-2025-23186
8.5

This vulnerability in SAP NetWeaver Application Server ABAP allows authenticated attackers to craft RFC requests that expose credentials for remote se...

Apr 8, 2025
CVE-2024-52899
8.5

This vulnerability allows authenticated users to inject malicious parameters into JDBC URLs in IBM Data Virtualization Manager for z/OS, potentially l...

Nov 26, 2024
CVE-2024-21513
8.5

This vulnerability allows arbitrary Python code execution in langchain-experimental when using VectorSQLDatabaseChain. Attackers who can control input...

Jul 15, 2024
CVE-2023-22677
8.5

CVE-2023-22677 is a code injection vulnerability in the WordPress WP Booklet plugin that allows remote attackers to execute arbitrary code on affected...

Dec 29, 2023
CVE-2023-43651
8.5

This vulnerability allows authenticated users of JumpServer to exploit MongoDB sessions through the WEB CLI interface to execute arbitrary commands, l...

Sep 27, 2023
CVE-2022-2636
8.5

CVE-2022-2636 is a code injection vulnerability in Hestia Control Panel that allows authenticated users to execute arbitrary code on the server. This ...

Aug 5, 2022
CVE-2021-39144
8.5

CVE-2021-39144 is a remote code execution vulnerability in XStream library versions before 1.4.18. Attackers with sufficient privileges can execute ar...

Aug 23, 2021
CVE-2024-56373
8.4

This vulnerability allows DAG authors with existing permissions to manipulate Airflow's database to execute arbitrary code in the web-server context w...

Feb 24, 2026
CVE-2025-67750
8.4

CVE-2025-67750 is a remote code execution vulnerability in Lightning Flow Scanner where maliciously crafted flow metadata files can execute arbitrary ...

Dec 12, 2025
CVE-2025-11093
8.4

This CVE describes an arbitrary code execution vulnerability in WSO2 integration products where authenticated users with elevated privileges (administ...

Nov 5, 2025
CVE-2025-46579
8.4

This CVE describes a DDE injection vulnerability in GoldenDB database products that allows attackers to embed malicious DDE expressions in files. When...

Apr 27, 2025
CVE-2024-6982
8.4

A remote code execution vulnerability in parisneo/lollms version 9.8 allows attackers to bypass Python sandbox restrictions and execute arbitrary comm...

Mar 20, 2025
CVE-2024-45271
8.4

An unauthenticated local attacker can gain administrative privileges by deploying a malicious configuration file due to improper input validation. Thi...

Oct 15, 2024
CVE-2024-33228
8.4

This vulnerability allows attackers to escalate privileges and execute arbitrary code by sending crafted IOCTL requests to the segwindrvx64.sys driver...

May 22, 2024
CVE-2024-23727
8.4

This vulnerability allows remote attackers to execute arbitrary JavaScript code in the YI Smart Kami Vision Android app through an implicit intent to ...

Mar 28, 2024
CVE-2023-35897
8.4

This CVE describes a DLL hijacking vulnerability in IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments. A local authenticate...

Oct 6, 2023
CVE-2023-34999
8.4

A command injection vulnerability in RTS VLink Virtual Matrix Software allows authenticated attackers to execute arbitrary commands via the admin web ...

Sep 18, 2023
CVE-2025-43010
8.3

This vulnerability allows authenticated SAP users with standard authorization to remotely execute a function module that can replace arbitrary ABAP pr...

May 13, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,161 CVEs classified as CWE-94, with 529 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free