CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,161)
This CVE describes a code injection vulnerability in the ScottCart WordPress plugin that allows attackers to execute arbitrary code on affected system...
Oct 28, 2024This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running vulnerable versions of Time Clock or Time C...
Oct 18, 2024CVE-2024-0220 is a cryptographic vulnerability in B&R Automation Studio Upgrade Service and B&R Technology Guarding that allows network-based attacker...
Feb 22, 2024This vulnerability exploits Unicode's bidirectional text algorithm to create source code that appears benign to human reviewers but contains malicious...
Nov 1, 2021CVE-2021-29465 is a critical vulnerability in Discord-Recon bot versions 0.0.3 and earlier that allows remote attackers to overwrite arbitrary files o...
Apr 22, 2021This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by ...
Jan 21, 2026CVE-2025-67509 is a read-only bypass vulnerability in Neuron AI framework's MySQLSelectTool that allows file writing via SQL injection. Attackers who ...
Dec 10, 2025IBM Integration Bus for z/OS is vulnerable to code injection by privileged users with access to the installation directory. This allows authenticated ...
Jul 7, 2025This vulnerability allows remote code execution through insecure deserialization in Garden's cryo library dependency. Attackers with Kubernetes cluste...
Oct 9, 2023This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects into generated documents by controlling the argument of the `addJS` metho...
Feb 19, 2026CVE-2024-39148 allows unauthenticated remote attackers to execute arbitrary operating system commands as root on KerOS systems by exploiting improper ...
Dec 1, 2025This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress servers running the vulnerable Catalog Importer, Scrape...
Sep 11, 2025The Phoneservice module contains a code injection vulnerability (CWE-94) that allows attackers to execute arbitrary code by injecting malicious input....
Apr 17, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected NETGEAR WiFi routers. Attackers can gain full control...
Feb 5, 2025This vulnerability allows administrators to configure insecure captive portal scripts in Arista EOS devices, potentially enabling remote code executio...
Jan 10, 2025A remote code execution vulnerability in Snyk Code Agent allows attackers to execute arbitrary code within the container. All versions of Code Agent a...
Dec 6, 2024This vulnerability allows attackers to execute arbitrary JavaScript code in the Super Unlimited Video Downloader Android app through a vulnerable comp...
Nov 11, 2024This vulnerability allows attackers to execute arbitrary JavaScript code through the MainActivity component in the Video Downloader Pro & Browser Andr...
Nov 11, 2024This vulnerability in Moodle allows authenticated users with question editing permissions to execute arbitrary code through calculated question types....
Nov 7, 2024This vulnerability allows attackers to execute arbitrary JavaScript code in the Android video downloader app via a vulnerable component. It affects us...
Oct 30, 2024This vulnerability allows low-privileged remote attackers to modify firewall configuration through environment variables, potentially causing denial o...
Sep 10, 2024A low-privileged remote attacker can modify OSPF service configuration through environment variables OSPF_INTERFACE.SIMPLE_KEY and OSPF_INTERFACE.DIGE...
Sep 10, 2024This vulnerability allows low-privileged remote attackers to modify firewall configuration settings through the FW_PORTFORWARDING.SRC_IP environment v...
Sep 10, 2024This vulnerability allows remote attackers to execute arbitrary code on Cobham SAILOR VSAT Ku systems via a crafted script targeting the acu_web compo...
Apr 12, 2024This vulnerability in ConnectWise ScreenConnect allows man-in-the-middle attackers to send crafted messages that can lead to remote code execution. It...
Feb 1, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on EdgeConnect SD-WAN Orchestrator systems if certain precond...
Aug 22, 2023This vulnerability in Auto-GPT allows malicious Python code executed via the application's commands to overwrite the docker-compose.yml file, enabling...
Jul 13, 2023CVE-2023-0788 is a code injection vulnerability in phpMyFAQ that allows attackers to execute arbitrary code on affected systems. This affects all user...
Feb 12, 2023CVE-2021-40487 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code o...
Oct 13, 2021This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to create arbitrary automations without proper authoriz...
Sep 9, 2025This CVE describes a code injection vulnerability in DELMIA Apriso manufacturing software that allows attackers to execute arbitrary code on affected ...
Aug 4, 2025This vulnerability allows remote code execution if an attacker obtains session administrator credentials for affected ASPECT systems. It affects multi...
May 22, 2025This is a critical buffer overflow vulnerability in Alpine Halo9 devices that allows network-adjacent attackers to execute arbitrary code with root pr...
Jan 31, 2025This is a remote code execution vulnerability in Craft CMS versions 4 and 5 that allows attackers to execute arbitrary code on affected systems. The v...
Jan 18, 2025A Client-Side Template Injection (CSTI) vulnerability in Taiga's project creation component allows remote attackers to execute arbitrary JavaScript co...
Nov 25, 2024Dell OpenManage Enterprise versions 4.1 and earlier contain a code injection vulnerability that allows authenticated attackers with low privileges to ...
Oct 17, 2024Scriptcase v9.10.023 and earlier contains a vulnerability in the nm_zip function that allows remote attackers to execute arbitrary code on affected sy...
Oct 1, 2024This CVE describes an eval injection vulnerability in InVesalius's DICOM file reader that allows attackers to execute arbitrary code by loading a mali...
Aug 23, 2024This vulnerability allows authenticated attackers to execute arbitrary code on Linksys E2500 routers via the hnd_parentalctrl_unblock function. Attack...
Jul 24, 2024This vulnerability in Westermo Lynx devices allows attackers with device access to execute arbitrary code, potentially compromising device functionali...
Feb 6, 2024This vulnerability allows attackers to execute arbitrary code during the early boot sequence of Aruba 9200 and 9000 Series Controllers and Gateways. S...
Sep 6, 2023This vulnerability allows attackers to inject malicious code into specific parameters of a web application, which is then executed when legitimate use...
Mar 10, 2022This vulnerability in Samsung's TEEGRIS secure OS allows attackers to bypass caller verification checks in SMC calls, potentially compromising the Tru...
Oct 6, 2021CVE-2025-33250 is a remote code execution vulnerability in NVIDIA's NeMo Framework that allows attackers to execute arbitrary code on affected systems...
Feb 18, 2026The NVIDIA NeMo Framework vulnerability allows attackers to inject malicious code through crafted data inputs. Successful exploitation could lead to r...
Feb 18, 2026NVIDIA Megatron Bridge contains a code injection vulnerability in a data shuffling tutorial component. Successful exploitation could allow attackers t...
Feb 18, 2026CVE-2025-65715 is a remote code execution vulnerability in Visual Studio Code's Code Runner extension that allows attackers to execute arbitrary code ...
Feb 16, 2026NVIDIA Megatron-LM contains a code injection vulnerability (CWE-94) where malicious data can lead to arbitrary code execution. This affects all platfo...
Feb 3, 2026This vulnerability in Salt's junos execution module allows remote code execution through unsafe YAML deserialization. Attackers can craft malicious YA...
Jan 30, 2026The browserstack-local Node.js package version 1.5.8 contains a command injection vulnerability due to improper sanitization of the logfile variable i...
Jan 28, 2026About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,161 CVEs classified as CWE-94, with 529 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free