CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,167
Total CVEs
531
Critical
517
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 10
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Google 7
9 Craftcms 7
10 Moodle 7

All Code Injection CVEs (1,167)

CVE-2023-34195
7.8

This vulnerability allows arbitrary code execution during the DXE phase of UEFI boot process in InsydeH2O firmware. Attackers can set a UEFI variable ...

Sep 18, 2023
CVE-2023-32418
7.8

This vulnerability allows processing a malicious file to cause unexpected app termination or arbitrary code execution on affected macOS systems. It af...

Jul 27, 2023
CVE-2023-1049
7.8

This CVE-2023-1049 vulnerability allows code injection when a user opens a malicious project file in Schneider Electric's HMI software. Attackers can ...

Jun 14, 2023
CVE-2019-16283
7.8

This vulnerability in HP Softpaq installer allows attackers to execute arbitrary code by exploiting improper control of generation of code (CWE-94). I...

Jun 9, 2023
CVE-2023-33733
7.8

CVE-2023-33733 is a critical code injection vulnerability in Reportlab PDF library versions up to 3.6.12. Attackers can execute arbitrary code by tric...

Jun 5, 2023
CVE-2022-35743
7.8

This vulnerability allows remote code execution through the Microsoft Windows Support Diagnostic Tool (MSDT) when processing specially crafted files. ...

May 31, 2023
CVE-2023-0598
7.8

This CVE-2023-0598 vulnerability in GE Digital Proficy iFIX allows attackers to inject malicious configuration files into the web server execution pat...

Mar 16, 2023
CVE-2022-27537
7.8

This CVE describes vulnerabilities in the system BIOS of certain HP PC products that could allow attackers to execute arbitrary code, escalate privile...

Feb 1, 2023
CVE-2021-43811
7.8

This vulnerability allows arbitrary code execution through malicious YAML configuration files in Sockeye neural machine translation framework. Attacke...

Dec 8, 2021
CVE-2021-43208
7.8

CVE-2021-43208 is a remote code execution vulnerability in Microsoft 3D Viewer that allows attackers to execute arbitrary code by tricking users into ...

Nov 10, 2021
CVE-2021-42296
7.8

This vulnerability allows remote code execution through specially crafted Microsoft Word documents. Attackers can exploit this by tricking users into ...

Nov 10, 2021
CVE-2021-40485
7.8

CVE-2021-40485 is a remote code execution vulnerability in Microsoft Excel that allows attackers to execute arbitrary code by tricking users into open...

Oct 13, 2021
CVE-2021-22117
7.8

This vulnerability allows attackers with local filesystem access to add arbitrary plugins to RabbitMQ on Windows systems. It affects RabbitMQ Windows ...

May 18, 2021
CVE-2021-21415
7.8

CVE-2021-21415 is a remote code execution vulnerability in the Prisma VS Code extension that allows arbitrary code execution when auto-formatting or v...

Apr 29, 2021
CVE-2019-1157
7.8

CVE-2019-1157 is a remote code execution vulnerability in the Windows Jet Database Engine that allows attackers to execute arbitrary code on vulnerabl...

Aug 14, 2019
CVE-2026-27464
7.7

This vulnerability allows authenticated users in Metabase to extract sensitive information including database credentials via template evaluation in e...

Feb 21, 2026
CVE-2026-25153
7.7

This vulnerability allows attackers to execute arbitrary Python code on TechDocs build servers when configured with 'runIn: local'. Malicious actors w...

Jan 30, 2026
CVE-2025-25680
7.7

This vulnerability allows remote code execution on LSC Smart Connect Indoor PTZ Cameras when a specially crafted QR code is presented during Wi-Fi con...

Mar 11, 2025
CVE-2024-49362
7.7

Joplin desktop application has a remote code execution vulnerability where clicking malicious links in untrusted notes can execute arbitrary shell com...

Nov 14, 2024
CVE-2024-28893
7.7

This vulnerability in HP SoftPaq software allows attackers to execute arbitrary code by modifying configuration files after extraction. It affects sys...

May 1, 2024
CVE-2025-61488
7.6

A remote code execution vulnerability in SLiMS 9 Bulian allows attackers to execute arbitrary code via the scrap_image.php component. This affects all...

Oct 20, 2025
CVE-2025-9959
7.6

This vulnerability allows attackers to escape the Local Python execution environment sandbox in smolagents by exploiting incomplete validation of dund...

Sep 3, 2025
CVE-2024-47879
7.6

OpenRefine versions before 3.8.3 lack CSRF protection on the preview-expression command, allowing malicious websites to execute attacker-controlled Cl...

Oct 24, 2024
CVE-2024-48279
7.6

This CVE describes a HTML injection vulnerability in PHPGurukul's User Registration & Login and User Management System. Attackers can inject arbitrary...

Oct 15, 2024
CVE-2024-46639
7.6

A stored cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to inject malicious scripts into the Custom Fields Name text fi...

Sep 23, 2024
CVE-2024-36581
7.6

CVE-2024-36581 is a prototype pollution vulnerability in abw badger-database version 1.2.1 that allows attackers to modify JavaScript object prototype...

Jun 17, 2024
CVE-2024-31621
7.6

This vulnerability allows remote attackers to execute arbitrary code on FlowiseAI installations by sending crafted scripts to the api/v1 component. It...

Apr 29, 2024
CVE-2024-29399
7.6

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of GNU Savane by uploading a specially cra...

Apr 11, 2024
CVE-2024-21351
7.6

This vulnerability allows attackers to bypass Windows SmartScreen security checks, potentially enabling them to execute malicious files without proper...

Feb 13, 2024
CVE-2021-32706
7.6

CVE-2021-32706 is a code injection vulnerability in Pi-hole's web interface that allows attackers to execute arbitrary code, list directories, and ove...

Aug 4, 2021
CVE-2020-37178
7.5

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can cause applicati...

Feb 11, 2026
CVE-2025-69319
7.5

This CVE describes a code injection vulnerability in Beaver Builder Lite WordPress plugin that allows attackers to execute arbitrary code. It affects ...

Jan 22, 2026
CVE-2025-61590
7.5

This vulnerability allows remote code execution in Cursor AI code editor versions 1.6 and below through manipulation of Visual Studio Code workspace f...

Oct 3, 2025
CVE-2025-52218
7.5

CVE-2025-52218 is a content spoofing vulnerability in SelectZero Data Observability Platform that allows attackers to inject arbitrary text or limited...

Aug 26, 2025
CVE-2025-47988
7.5

This CVE describes a code injection vulnerability in Azure Monitor Agent that allows unauthorized attackers on adjacent networks to execute arbitrary ...

Jul 8, 2025
CVE-2023-31315
7.5

This AMD processor vulnerability allows malicious software with kernel-level (ring0) access to bypass System Management Mode (SMM) protections and mod...

Aug 12, 2024
CVE-2024-5979
7.5

This vulnerability in h2oai/h2o-3 version 3.46.0 allows attackers to call the main function of any class under the water.tools namespace via the run_t...

Jun 27, 2024
CVE-2024-32358
7.5

CVE-2024-32358 is a remote code execution vulnerability in JPress v5.1.0 that allows attackers to execute arbitrary code through crafted scripts in th...

Apr 25, 2024
CVE-2024-2097
7.5

This vulnerability allows authenticated malicious clients to send specially crafted LINQ queries to execute arbitrary code remotely on SCM servers. It...

Mar 27, 2024
CVE-2024-0400
7.5

This vulnerability allows authenticated malicious clients to execute arbitrary code on SCM Server by sending specially crafted LINQ queries that bypas...

Mar 27, 2024
CVE-2024-28396
7.5

This vulnerability allows remote attackers to execute arbitrary code on systems running MyPrestaModules ordersexport version 6.0.2 and earlier. Attack...

Mar 20, 2024
CVE-2024-24230
7.5

Komm.One CMS 10.4.2.14 has a Server-Side Template Injection vulnerability in the Velocity template engine that allows remote attackers to execute arbi...

Mar 18, 2024
CVE-2022-46070
7.5

CVE-2022-46070 is a Local File Inclusion vulnerability in GV-ASManager V6.0.1.0's GeoWebServer component that allows attackers to read arbitrary files...

Mar 11, 2024
CVE-2024-24278
7.5

This vulnerability in Teamwire Windows desktop client allows remote attackers to obtain sensitive information by sending a crafted payload to the mess...

Mar 5, 2024
CVE-2023-51770
7.5

CVE-2023-51770 is an arbitrary file read vulnerability in Apache DolphinScheduler that allows attackers to read sensitive files from the server filesy...

Feb 20, 2024
CVE-2023-45560
7.5

This vulnerability in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications by exploiting a leaked channel access token. Attack...

Nov 14, 2023
CVE-2020-36767
7.5

This vulnerability in tinyfiledialogs allows shell metacharacters in dialog box titles, messages, and other input fields, potentially enabling command...

Oct 30, 2023
CVE-2023-39685
7.5

This vulnerability in hjson-java allows attackers to cause Denial of Service (DoS) by sending specially crafted JSON strings. Applications using hjson...

Sep 1, 2023
CVE-2022-47879
7.5

This CVE describes a Remote Code Execution vulnerability in Jedox's /be/rpc.php endpoint that allows authenticated users to load arbitrary PHP classes...

May 12, 2023
CVE-2023-24709
7.5

This vulnerability in Paradox Security Systems IPR512 allows attackers to cause denial of service by exploiting injection vulnerabilities in login.htm...

Mar 21, 2023

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,167 CVEs classified as CWE-94, with 531 rated critical and 517 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free