CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,163
Total CVEs
529
Critical
515
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 10
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Google 7
9 Craftcms 7
10 Moodle 7

All Code Injection CVEs (1,163)

CVE-2025-57283
7.8

The browserstack-local Node.js package version 1.5.8 contains a command injection vulnerability due to improper sanitization of the logfile variable i...

Jan 28, 2026
CVE-2025-33233
7.8

CVE-2025-33233 is a code injection vulnerability in NVIDIA Merlin Transformers4Rec that could allow attackers to execute arbitrary code. This affects ...

Jan 20, 2026
CVE-2023-53940
7.8

Codigo Markdown Editor 1.0.1 contains a remote code execution vulnerability where attackers can craft malicious markdown files that execute arbitrary ...

Dec 18, 2025
CVE-2025-67748
7.8

Fickling versions before 0.1.6 incorrectly flagged unsafe pickle files as safe due to missing 'pty' module in the unsafe import blocklist. This vulner...

Dec 16, 2025
CVE-2025-55313
7.8

This vulnerability in Foxit PDF software allows arbitrary code execution when processing malicious PDF files. Attackers can exploit memory corruption ...

Dec 11, 2025
CVE-2025-66533
7.8

This CVE describes a code injection vulnerability in the GiveWP WordPress plugin that allows attackers to execute arbitrary shortcodes. It affects all...

Dec 9, 2025
CVE-2025-33183
7.8

This vulnerability in NVIDIA Isaac-GR00T allows attackers to inject malicious code through a Python component, potentially leading to remote code exec...

Nov 18, 2025
CVE-2025-33184
7.8

This CVE describes a code injection vulnerability in NVIDIA Isaac-GR00T's Python component that could allow attackers to execute arbitrary code. Succe...

Nov 18, 2025
CVE-2025-33178
7.8

The NVIDIA NeMo Framework contains a code injection vulnerability in its BERT services component that allows attackers to execute arbitrary code by se...

Nov 11, 2025
CVE-2025-23357
7.8

NVIDIA Megatron-LM contains a code injection vulnerability (CWE-94) where malicious data can lead to arbitrary code execution. This affects all platfo...

Nov 11, 2025
CVE-2025-23361
7.8

The NVIDIA NeMo Framework contains a vulnerability where malicious input can cause improper control of code generation, potentially leading to remote ...

Nov 11, 2025
CVE-2025-23353
7.8

NVIDIA Megatron-LM's msdp preprocessing script contains a code injection vulnerability (CWE-94) that allows attackers to execute arbitrary code by pro...

Sep 24, 2025
CVE-2025-23348
7.8

CVE-2025-23348 is a code injection vulnerability in NVIDIA's Megatron-LM pretrain_gpt script that allows attackers to execute arbitrary code by provid...

Sep 24, 2025
CVE-2025-23315
7.8

CVE-2025-23315 is a code injection vulnerability in NVIDIA NeMo Framework's export and deploy component that allows attackers to execute arbitrary cod...

Aug 26, 2025
CVE-2025-23307
7.8

NVIDIA NeMo Curator contains a code injection vulnerability (CWE-94) where malicious files can execute arbitrary code. This affects all platforms runn...

Aug 26, 2025
CVE-2025-23313
7.8

CVE-2025-23313 is a code injection vulnerability in NVIDIA's NeMo Framework NLP component that allows attackers to execute arbitrary code by providing...

Aug 26, 2025
CVE-2025-7361
7.8

A code injection vulnerability in NI LabVIEW allows arbitrary code execution when users open specially crafted VI files containing CIN nodes. This aff...

Jul 29, 2025
CVE-2025-3753
7.8

A remote code execution vulnerability exists in ROS 'rosbag' tool due to unsafe eval() usage on user input in the 'rosbag filter' command. Attackers c...

Jul 17, 2025
CVE-2024-39289
7.8

This CVE describes a remote code execution vulnerability in ROS's rosparam tool where attackers can execute arbitrary Python code by crafting maliciou...

Jul 17, 2025
CVE-2024-41148
7.8

This CVE allows local users to execute arbitrary Python code through the ROS rostopic command's 'hz' verb filter option. The vulnerability affects ROS...

Jul 17, 2025
CVE-2025-34079
EPSS 51.9% 7.8

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary commands with SYSTEM privileges on NSClient++ se...

Jul 2, 2025
CVE-2025-23265
7.8

CVE-2025-23265 is a code injection vulnerability in NVIDIA Megatron-LM's Python component that allows attackers to execute arbitrary code by providing...

Jun 24, 2025
CVE-2025-32801
7.8

CVE-2025-32801 allows attackers to load malicious hook libraries into Kea DHCP servers via configuration or API directives. This can lead to remote co...

May 28, 2025
CVE-2025-24243
7.8

This memory handling vulnerability in Apple operating systems allows arbitrary code execution when processing malicious files. Attackers can exploit t...

Mar 31, 2025
CVE-2025-0161
7.8

This vulnerability in IBM Security Verify Access Appliance allows local users to execute arbitrary code due to improper restrictions on code generatio...

Feb 20, 2025
CVE-2025-25943
7.8

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows local attackers to execute arbitrary code via the AP4_Stz2Atom component. This affects sys...

Feb 19, 2025
CVE-2025-24159
7.8

This CVE describes a validation logic vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privil...

Jan 27, 2025
CVE-2024-27856
7.8

This vulnerability allows processing a malicious file to cause unexpected app termination or arbitrary code execution on affected Apple devices. It af...

Jan 15, 2025
CVE-2025-21187
7.8

This vulnerability allows remote code execution in Microsoft Power Automate through improper control of generation of code (CWE-94). Attackers could e...

Jan 14, 2025
CVE-2024-30961
7.8

This CVE describes an insecure permissions vulnerability in ROS2 navigation2 that allows local attackers to execute arbitrary code via the error-throw...

Dec 5, 2024
CVE-2024-30963
7.8

A buffer overflow vulnerability in ROS2 navigation2 allows local attackers to execute arbitrary code by providing a malicious script. This affects sys...

Dec 5, 2024
CVE-2024-50804
7.8

This vulnerability allows a local attacker to execute arbitrary code with elevated privileges on systems running MSI Center Pro 2.1.37.0. By exploitin...

Nov 18, 2024
CVE-2024-52945
7.8

This vulnerability allows attackers to execute arbitrary code by loading malicious DLLs when users run specific NetBackup commands on Windows systems....

Nov 18, 2024
CVE-2024-9050
7.8

This vulnerability allows local unprivileged users to achieve privilege escalation and potentially execute arbitrary code as root. The flaw exists in ...

Oct 22, 2024
CVE-2024-8374
7.8

UltiMaker Cura 3D printing slicer versions 5.7.0-beta.1 through 5.7.2 contain a code injection vulnerability in the 3MF file reader. Attackers can cra...

Sep 3, 2024
CVE-2024-28699
7.8

A buffer overflow vulnerability in pdf2json v0.70 allows local attackers to execute arbitrary code by exploiting the GString::copy() and ImgOutputDev:...

Apr 22, 2024
CVE-2024-25376
7.8

This vulnerability allows a local attacker to execute arbitrary code by exploiting the MSI-based installer repair mode in Thesycon TUSBAudio software....

Apr 11, 2024
CVE-2024-24520
7.8

CVE-2024-24520 is a code injection vulnerability in Lepton CMS v7.0.0 that allows local attackers to execute arbitrary code via the upgrade.php file i...

Mar 21, 2024
CVE-2024-23208
7.8

This is a memory corruption vulnerability (CWE-94: Improper Control of Generation of Code) in Apple operating systems that allows an application to ex...

Jan 23, 2024
CVE-2023-32383
7.8

This vulnerability allows malicious applications to inject code into sensitive Xcode binaries on macOS systems. It affects macOS Monterey, Big Sur, an...

Jan 10, 2024
CVE-2023-6691
7.8

Cambium ePMP Force 300-25 version 4.7.0.1 contains a code injection vulnerability that allows remote attackers to execute arbitrary code with root pri...

Dec 18, 2023
CVE-2023-6288
7.8

This vulnerability allows attackers to inject malicious code into Remote Desktop Manager on macOS by manipulating the DYLIB_INSERT_LIBRARIES environme...

Dec 6, 2023
CVE-2023-44141
7.8

This vulnerability allows local attackers to execute arbitrary code by tricking legitimate users into opening malicious markdown files in Inkdrop. It ...

Oct 30, 2023
CVE-2023-36718
7.8

CVE-2023-36718 is a remote code execution vulnerability in Microsoft's Virtual Trusted Platform Module (vTPM) that allows authenticated attackers to e...

Oct 10, 2023
CVE-2023-41444
7.8

This vulnerability in Binalyze IREC.sys driver allows a local attacker to execute arbitrary code with kernel privileges via a specific function. It af...

Sep 28, 2023
CVE-2023-41984
7.8

CVE-2023-41984 is a memory handling vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileg...

Sep 27, 2023
CVE-2023-34195
7.8

This vulnerability allows arbitrary code execution during the DXE phase of UEFI boot process in InsydeH2O firmware. Attackers can set a UEFI variable ...

Sep 18, 2023
CVE-2023-32418
7.8

This vulnerability allows processing a malicious file to cause unexpected app termination or arbitrary code execution on affected macOS systems. It af...

Jul 27, 2023
CVE-2023-1049
7.8

This CVE-2023-1049 vulnerability allows code injection when a user opens a malicious project file in Schneider Electric's HMI software. Attackers can ...

Jun 14, 2023
CVE-2019-16283
7.8

This vulnerability in HP Softpaq installer allows attackers to execute arbitrary code by exploiting improper control of generation of code (CWE-94). I...

Jun 9, 2023

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,163 CVEs classified as CWE-94, with 529 rated critical and 515 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free