CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,186
Total CVEs
540
Critical
527
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 11
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Ivanti 8
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,186)

CVE-2021-24209
7.2

This vulnerability allows authenticated WordPress administrators (or users with admin privileges) to execute arbitrary code on servers running vulnera...

Apr 5, 2021
CVE-2021-3273
7.2

This vulnerability allows authenticated Nagios XI administrators to execute arbitrary code through code injection in the graphtemplates.php component....

Feb 25, 2021
CVE-2020-35734
7.2

This vulnerability allows authenticated users in Batflat CMS to inject malicious code through user profile fields, leading to remote code execution. I...

Feb 15, 2021
CVE-2021-23337
7.2

Lodash versions before 4.17.21 contain a command injection vulnerability in the template function that allows attackers to execute arbitrary commands ...

Feb 15, 2021
CVE-2021-20187
7.2

This vulnerability allows Moodle site administrators to execute arbitrary PHP code via a PHP include during Shibboleth authentication. It affects Mood...

Jan 28, 2021
CVE-2020-8243
7.2

This vulnerability allows authenticated attackers to upload custom templates through the Pulse Connect Secure admin web interface, leading to arbitrar...

Sep 30, 2020
CVE-2019-7177
7.2

CVE-2019-7177 is a code injection vulnerability in Pexip Infinity that allows authenticated administrators to execute arbitrary code on nodes. This af...

Sep 25, 2020
CVE-2020-6318
7.2

CVE-2020-6318 is a critical code injection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform that allows remote attackers to execute arbitr...

Sep 9, 2020
CVE-2026-0771
7.1

This vulnerability allows remote attackers to execute arbitrary Python code on Langflow installations through Python function components. Attackers ca...

Jan 23, 2026
CVE-2025-66448
7.1

This vulnerability in vLLM allows remote code execution when loading model configurations containing auto_map entries. Attackers can create a seemingl...

Dec 1, 2025
CVE-2024-10001
7.1

A code injection vulnerability in GitHub Enterprise Server allows attackers to inject malicious code via the identity property in message handling, en...

Jan 29, 2025
CVE-2024-21643
7.1

This vulnerability in Microsoft.IdentityModel allows attackers to make arbitrary HTTP GET requests by exploiting trust in the 'jku' claim within Signe...

Jan 10, 2024
CVE-2023-40313
7.1

This vulnerability allows remote attackers to execute arbitrary Java code on OpenNMS Horizon and Meridian servers running vulnerable versions. It affe...

Aug 17, 2023
CVE-2023-26436
7.1

CVE-2023-26436 is a Java deserialization vulnerability in OX App Suite's documentconverterws API that allows authenticated attackers on local networks...

Jun 20, 2023
CVE-2022-25760
7.1

CVE-2022-25760 is a code injection vulnerability in the accesslog npm package that allows attackers to execute arbitrary JavaScript code on the host s...

Mar 17, 2022
CVE-2020-7745
7.1

CVE-2020-7745 is a backdoor vulnerability in MintegralAdSDK that allows Mintegral and their advertising partners to remotely execute arbitrary code on...

Oct 19, 2020
CVE-2023-5623
7.0

This vulnerability in NNM (Network Node Manager) allows low-privileged users to execute arbitrary code with SYSTEM privileges when NNM is installed in...

Oct 26, 2023
CVE-2025-42895
6.9

This vulnerability in SAP HANA JDBC Client allows high-privilege locally authenticated users to supply crafted connection parameters that lead to unau...

Nov 11, 2025
CVE-2024-12908
6.9

This vulnerability in Delinea Secret Server's protocol handler allows remote code execution through URI comparison flaws before normalization. Attacke...

Dec 26, 2024
CVE-2026-23946
6.8

This critical vulnerability allows authenticated staff users in Tendenci CMS to execute arbitrary code on the server through unsafe Python pickle dese...

Jan 22, 2026
CVE-2025-65829
6.8

This CVE describes a missing Secure Boot implementation on ESP32 SoC devices, specifically affecting Meatmeet basestation devices. Attackers with phys...

Dec 10, 2025
CVE-2025-5717
6.8

This CVE describes an authenticated remote code execution vulnerability in WSO2 products where administrators can deploy malicious Java code through S...

Sep 23, 2025
CVE-2024-41643
6.8

This vulnerability allows a physically proximate attacker to execute arbitrary code on Arris NVG443B routers via the cshell login component. It affect...

Mar 26, 2025
CVE-2019-8900
6.8

A SecureROM vulnerability in certain Apple devices allows unauthenticated local attackers with physical access to execute arbitrary code during boot v...

Feb 21, 2025
CVE-2024-7425
6.8

The WP ALL Export Pro WordPress plugin has an authentication bypass vulnerability that allows authenticated attackers with Shop Manager or higher priv...

Feb 7, 2025
CVE-2024-36361
6.8

CVE-2024-36361 allows remote code execution in Pug template engine when untrusted input is passed to specific compilation functions. Applications usin...

May 24, 2024
CVE-2025-37157
6.7

A command injection vulnerability in AOS-CX Operating System allows authenticated remote attackers to execute arbitrary commands on affected systems. ...

Nov 18, 2025
CVE-2024-48829
6.7

This vulnerability allows a high-privileged attacker with local access to Dell SmartFabric OS10 switches to execute arbitrary code through improper in...

Nov 12, 2025
CVE-2025-1976
KEV 6.7

This vulnerability allows local admin users on Brocade Fabric OS to escalate privileges to root level, enabling arbitrary code execution. It affects F...

Apr 24, 2025
CVE-2025-30013
6.7

SAP ERP BW Business Content contains function modules vulnerable to OS command injection, allowing attackers to execute arbitrary commands on the unde...

Apr 8, 2025
CVE-2024-56448
6.7

This vulnerability allows improper access control in the home screen widget module, potentially enabling attackers to disrupt device availability. It ...

Jan 8, 2025
CVE-2024-42598
6.7

SeaCMS 13.0 has an authenticated remote code execution vulnerability in admin_editplayer.php where attackers can bypass file restrictions to write and...

Aug 20, 2024
CVE-2025-60114
6.6

This CVE describes a code injection vulnerability in the YayCommerce YayCurrency WordPress plugin that allows attackers to execute arbitrary code on a...

Sep 26, 2025
CVE-2024-41712
6.6

This vulnerability allows authenticated attackers to execute arbitrary commands on Mitel MiCollab systems through command injection in the Web Confere...

Oct 21, 2024
CVE-2024-45933
6.6

OnlineNewsSite v1.0 contains a stored XSS vulnerability in the admin post editor that allows attackers to inject malicious JavaScript into news articl...

Oct 7, 2024
CVE-2024-3788
6.6

This vulnerability in WBSAirback 21.02.04 allows improper neutralization of Server-Side Includes (SSI) through the License endpoint at /admin/CDPUsers...

May 14, 2024
CVE-2023-35701
6.6

This CVE describes a code injection vulnerability in Apache Hive's JDBC driver that allows arbitrary code execution on client systems. Attackers can e...

May 3, 2024
CVE-2026-1245
6.5

A code injection vulnerability in binary-parser library versions before 2.3.0 allows attackers to execute arbitrary JavaScript code when untrusted inp...

Jan 20, 2026
CVE-2025-60070
6.5

This CVE describes a code injection vulnerability in the Molla WordPress theme that allows attackers to execute arbitrary code on affected websites. T...

Dec 18, 2025
CVE-2025-60068
6.5

This CVE describes a code injection vulnerability in the Javo Core WordPress plugin that allows attackers to execute arbitrary code on affected system...

Dec 18, 2025
CVE-2025-64320
6.5

This vulnerability allows attackers to inject malicious code into Salesforce Agentforce Vibes Extension's LLM prompting system. When exploited, it cou...

Nov 4, 2025
CVE-2025-10875
6.5

This vulnerability allows attackers to inject malicious code through improperly sanitized input used for LLM prompting in Salesforce Mulesoft Anypoint...

Nov 4, 2025
CVE-2025-54019
6.5

This CVE describes a code injection vulnerability in the Bearsthemes Alone WordPress theme that allows attackers to execute arbitrary code on affected...

Aug 20, 2025
CVE-2025-8878
6.5

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the ProfilePress plugin. Attackers can potential...

Aug 16, 2025
CVE-2025-39483
6.5

This CVE describes a code injection vulnerability in the Eventer WordPress plugin that allows attackers to execute arbitrary code through shortcode ma...

Aug 14, 2025
CVE-2025-46000
6.5

This CVE describes an arbitrary file upload vulnerability in Filemanager v2.5.0 that allows attackers to upload crafted SVG files containing malicious...

Jul 18, 2025
CVE-2025-0618
6.5

This vulnerability allows a malicious actor to cause a persistent denial of service in FireEye EDR agents by sending a specially crafted tamper protec...

Apr 23, 2025
CVE-2024-13557
6.5

The Shortcodes by United Themes WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. Th...

Mar 29, 2025
CVE-2025-26924
6.5

This vulnerability allows attackers to inject malicious code through shortcodes in the Ohio Extra WordPress plugin, potentially leading to remote code...

Mar 15, 2025
CVE-2024-13815
6.5

The Listingo WordPress theme allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability aff...

Mar 5, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,186 CVEs classified as CWE-94, with 540 rated critical and 527 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free