CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,161
Total CVEs
529
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 10
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Google 7
9 Craftcms 7
10 Moodle 7

All Code Injection CVEs (1,161)

CVE-2024-50492
8.3

This CVE describes a code injection vulnerability in the ScottCart WordPress plugin that allows attackers to execute arbitrary code on affected system...

Oct 28, 2024
CVE-2024-9593
8.3

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running vulnerable versions of Time Clock or Time C...

Oct 18, 2024
CVE-2024-0220
8.3

CVE-2024-0220 is a cryptographic vulnerability in B&R Automation Studio Upgrade Service and B&R Technology Guarding that allows network-based attacker...

Feb 22, 2024
CVE-2021-42574
8.3

This vulnerability exploits Unicode's bidirectional text algorithm to create source code that appears benign to human reviewers but contains malicious...

Nov 1, 2021
CVE-2021-29465
8.3

CVE-2021-29465 is a critical vulnerability in Discord-Recon bot versions 0.0.3 and earlier that allows remote attackers to overwrite arbitrary files o...

Apr 22, 2021
CVE-2026-20045
KEV 8.2

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by ...

Jan 21, 2026
CVE-2025-67509
8.2

CVE-2025-67509 is a read-only bypass vulnerability in Neuron AI framework's MySQLSelectTool that allows file writing via SQL injection. Attackers who ...

Dec 10, 2025
CVE-2025-36014
8.2

IBM Integration Bus for z/OS is vulnerable to code injection by privileged users with access to the installation directory. This allows authenticated ...

Jul 7, 2025
CVE-2023-44392
8.2

This vulnerability allows remote code execution through insecure deserialization in Garden's cryo library dependency. Attackers with Kubernetes cluste...

Oct 9, 2023
CVE-2026-25755
8.1

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects into generated documents by controlling the argument of the `addJS` metho...

Feb 19, 2026
CVE-2024-39148
8.1

CVE-2024-39148 allows unauthenticated remote attackers to execute arbitrary operating system commands as root on KerOS systems by exploiting improper ...

Dec 1, 2025
CVE-2025-8417
8.1

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress servers running the vulnerable Catalog Importer, Scrape...

Sep 11, 2025
CVE-2025-1532
8.1

The Phoneservice module contains a code injection vulnerability (CWE-94) that allows attackers to execute arbitrary code by injecting malicious input....

Apr 17, 2025
CVE-2025-25246
8.1

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected NETGEAR WiFi routers. Attackers can gain full control...

Feb 5, 2025
CVE-2024-9132
8.1

This vulnerability allows administrators to configure insecure captive portal scripts in Arista EOS devices, potentially enabling remote code executio...

Jan 10, 2025
CVE-2024-21571
8.1

A remote code execution vulnerability in Snyk Code Agent allows attackers to execute arbitrary code within the container. All versions of Code Agent a...

Dec 6, 2024
CVE-2024-46963
8.1

This vulnerability allows attackers to execute arbitrary JavaScript code in the Super Unlimited Video Downloader Android app through a vulnerable comp...

Nov 11, 2024
CVE-2024-46966
8.1

This vulnerability allows attackers to execute arbitrary JavaScript code through the MainActivity component in the Video Downloader Pro & Browser Andr...

Nov 11, 2024
CVE-2024-43425
8.1

This vulnerability in Moodle allows authenticated users with question editing permissions to execute arbitrary code through calculated question types....

Nov 7, 2024
CVE-2024-42041
8.1

This vulnerability allows attackers to execute arbitrary JavaScript code in the Android video downloader app via a vulnerable component. It affects us...

Oct 30, 2024
CVE-2024-43393
8.1

This vulnerability allows low-privileged remote attackers to modify firewall configuration through environment variables, potentially causing denial o...

Sep 10, 2024
CVE-2024-43389
8.1

A low-privileged remote attacker can modify OSPF service configuration through environment variables OSPF_INTERFACE.SIMPLE_KEY and OSPF_INTERFACE.DIGE...

Sep 10, 2024
CVE-2024-43391
8.1

This vulnerability allows low-privileged remote attackers to modify firewall configuration settings through the FW_PORTFORWARDING.SRC_IP environment v...

Sep 10, 2024
CVE-2023-44857
8.1

This vulnerability allows remote attackers to execute arbitrary code on Cobham SAILOR VSAT Ku systems via a crafted script targeting the acu_web compo...

Apr 12, 2024
CVE-2023-47257
8.1

This vulnerability in ConnectWise ScreenConnect allows man-in-the-middle attackers to send crafted messages that can lead to remote code execution. It...

Feb 1, 2024
CVE-2023-37424
8.1

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on EdgeConnect SD-WAN Orchestrator systems if certain precond...

Aug 22, 2023
CVE-2023-37273
8.1

This vulnerability in Auto-GPT allows malicious Python code executed via the application's commands to overwrite the docker-compose.yml file, enabling...

Jul 13, 2023
CVE-2023-0788
8.1

CVE-2023-0788 is a code injection vulnerability in phpMyFAQ that allows attackers to execute arbitrary code on affected systems. This affects all user...

Feb 12, 2023
CVE-2021-40487
8.1

CVE-2021-40487 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code o...

Oct 13, 2021
CVE-2025-9539
8.0

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary automations without proper authoriz...

Sep 9, 2025
CVE-2025-6204
KEV 8.0

This CVE describes a code injection vulnerability in DELMIA Apriso manufacturing software that allows attackers to execute arbitrary code on affected ...

Aug 4, 2025
CVE-2024-9639
8.0

This vulnerability allows remote code execution if an attacker obtains session administrator credentials for affected ASPECT systems. It affects multi...

May 22, 2025
CVE-2024-23963
8.0

This is a critical buffer overflow vulnerability in Alpine Halo9 devices that allows network-adjacent attackers to execute arbitrary code with root pr...

Jan 31, 2025
CVE-2025-23209
KEV 8.0

This is a remote code execution vulnerability in Craft CMS versions 4 and 5 that allows attackers to execute arbitrary code on affected systems. The v...

Jan 18, 2025
CVE-2024-53554
8.0

A Client-Side Template Injection (CSTI) vulnerability in Taiga's project creation component allows remote attackers to execute arbitrary JavaScript co...

Nov 25, 2024
CVE-2024-45766
8.0

Dell OpenManage Enterprise versions 4.1 and earlier contain a code injection vulnerability that allows authenticated attackers with low privileges to ...

Oct 17, 2024
CVE-2024-46080
8.0

Scriptcase v9.10.023 and earlier contains a vulnerability in the nm_zip function that allows remote attackers to execute arbitrary code on affected sy...

Oct 1, 2024
CVE-2024-42845
EPSS 63.7% 8.0

This CVE describes an eval injection vulnerability in InVesalius's DICOM file reader that allows attackers to execute arbitrary code by loading a mali...

Aug 23, 2024
CVE-2024-40495
8.0

This vulnerability allows authenticated attackers to execute arbitrary code on Linksys E2500 routers via the hnd_parentalctrl_unblock function. Attack...

Jul 24, 2024
CVE-2023-45735
8.0

This vulnerability in Westermo Lynx devices allows attackers with device access to execute arbitrary code, potentially compromising device functionali...

Feb 6, 2024
CVE-2023-38484
8.0

This vulnerability allows attackers to execute arbitrary code during the early boot sequence of Aruba 9200 and 9000 Series Controllers and Gateways. S...

Sep 6, 2023
CVE-2022-24915
8.0

This vulnerability allows attackers to inject malicious code into specific parameters of a web application, which is then executed when legitimate use...

Mar 10, 2022
CVE-2021-25470
7.9

This vulnerability in Samsung's TEEGRIS secure OS allows attackers to bypass caller verification checks in SMC calls, potentially compromising the Tru...

Oct 6, 2021
CVE-2025-33250
7.8

CVE-2025-33250 is a remote code execution vulnerability in NVIDIA's NeMo Framework that allows attackers to execute arbitrary code on affected systems...

Feb 18, 2026
CVE-2025-33236
7.8

The NVIDIA NeMo Framework vulnerability allows attackers to inject malicious code through crafted data inputs. Successful exploitation could lead to r...

Feb 18, 2026
CVE-2025-33240
7.8

NVIDIA Megatron Bridge contains a code injection vulnerability in a data shuffling tutorial component. Successful exploitation could allow attackers t...

Feb 18, 2026
CVE-2025-65715
7.8

CVE-2025-65715 is a remote code execution vulnerability in Visual Studio Code's Code Runner extension that allows attackers to execute arbitrary code ...

Feb 16, 2026
CVE-2026-24149
7.8

NVIDIA Megatron-LM contains a code injection vulnerability (CWE-94) where malicious data can lead to arbitrary code execution. This affects all platfo...

Feb 3, 2026
CVE-2025-62348
7.8

This vulnerability in Salt's junos execution module allows remote code execution through unsafe YAML deserialization. Attackers can craft malicious YA...

Jan 30, 2026
CVE-2025-57283
7.8

The browserstack-local Node.js package version 1.5.8 contains a command injection vulnerability due to improper sanitization of the logfile variable i...

Jan 28, 2026

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,161 CVEs classified as CWE-94, with 529 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free