CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,145
Total CVEs
517
Critical
509
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,145)

CVE-2021-38450
9.9

This vulnerability allows remote code execution by exploiting improper input sanitization in industrial controllers. Attackers can inject malicious co...

Oct 27, 2021
CVE-2021-27602
9.9

This vulnerability allows authorized users in SAP Commerce Backoffice to inject malicious code into source rules, which are translated to Drools rules...

Apr 13, 2021
CVE-2021-21433
9.9

CVE-2021-21433 is a critical remote code execution vulnerability in Discord Recon Server version 0.0.1, allowing attackers to execute arbitrary comman...

Apr 9, 2021
CVE-2026-27966
9.8

This vulnerability in Langflow's CSV Agent node allows attackers to execute arbitrary Python and OS commands on the server via prompt injection, leadi...

Feb 26, 2026
CVE-2026-27744
9.8

The SPIP tickets plugin contains an unauthenticated remote code execution vulnerability in forum preview handling. Attackers can inject malicious cont...

Feb 25, 2026
CVE-2025-71243
9.8

The Saisies plugin for SPIP contains a critical Remote Code Execution vulnerability (CWE-94: Improper Control of Generation of Code) that allows attac...

Feb 19, 2026
CVE-2026-27174
9.8

CVE-2026-27174 allows unauthenticated attackers to execute arbitrary PHP code on MajorDoMo home automation systems via the admin panel's PHP console. ...

Feb 18, 2026
CVE-2020-37186
9.8

CVE-2020-37186 is a critical remote code execution vulnerability in Chevereto image hosting software. Attackers can inject malicious PHP code during d...

Feb 11, 2026
CVE-2025-69872
9.8

This vulnerability in DiskCache (python-diskcache) allows arbitrary code execution when an attacker with write access to the cache directory injects m...

Feb 11, 2026
CVE-2026-1615
9.8

The jsonpath package is vulnerable to arbitrary code execution via malicious JSON Path expressions. Attackers can inject JavaScript code that gets exe...

Feb 9, 2026
CVE-2025-69983
9.8

CVE-2025-69983 is a critical remote code execution vulnerability in FUXA v1.2.7 that allows attackers to execute arbitrary system commands through mal...

Feb 3, 2026
CVE-2026-25141
9.8

This CVE describes a code injection vulnerability in Orval, a tool that generates TypeScript clients from OpenAPI/Swagger specifications. The incomple...

Jan 30, 2026
CVE-2026-1340
EPSS 40.2% 9.8

This critical vulnerability in Ivanti Endpoint Manager Mobile allows unauthenticated attackers to inject malicious code and execute arbitrary commands...

Jan 29, 2026
CVE-2026-1281
KEV EPSS 54.3% 9.8

CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to execute arb...

Jan 29, 2026
CVE-2025-69564
9.8

CVE-2025-69564 is a critical SQL injection vulnerability in code-projects Mobile Shop Management System 1.0 that allows attackers to execute arbitrary...

Jan 27, 2026
CVE-2026-22709
9.8

This vulnerability in vm2 sandbox for Node.js allows attackers to bypass Promise callback sanitization and escape the sandbox environment. Attackers c...

Jan 26, 2026
CVE-2026-0768
9.8

CVE-2026-0768 is a critical remote code execution vulnerability in Langflow that allows unauthenticated attackers to execute arbitrary Python code on ...

Jan 23, 2026
CVE-2026-0761
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary Python code on systems running vulnerable versions of Foundat...

Jan 23, 2026
CVE-2025-55423
9.8

A critical command injection vulnerability in ipTIME routers allows attackers to execute arbitrary operating system commands by injecting malicious in...

Jan 20, 2026
CVE-2025-11837
9.8

This critical vulnerability in Malware Remover allows remote attackers to bypass security protections through improper code generation control. Attack...

Jan 2, 2026
CVE-2025-66848
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands remotely on affected JD Cloud NAS routers. Attackers can gain full c...

Dec 30, 2025
CVE-2025-68952
9.8

Eigent multi-agent Workforce version 0.0.60 contains a 1-click Remote Code Execution vulnerability that allows attackers to execute arbitrary code on ...

Dec 27, 2025
CVE-2025-13773
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running the Print Invoice & Delivery Notes for WooC...

Dec 24, 2025
CVE-2025-65854
9.8

Insecure permissions in MineAdmin v3.x scheduled tasks allow attackers to execute arbitrary commands, leading to remote code execution and full accoun...

Dec 12, 2025
CVE-2025-67727
9.8

This CVE describes a GitHub Actions workflow vulnerability in Parse Server that grants elevated permissions to CI/CD pipelines. It allows unauthorized...

Dec 12, 2025
CVE-2025-65294
9.8

Aqara Hub devices contain an undocumented remote access mechanism that allows attackers to execute arbitrary commands without authentication. This vul...

Dec 10, 2025
CVE-2025-65602
9.8

An unauthenticated remote code execution vulnerability in ChanCMS v3.3.4 allows attackers to execute arbitrary code via template injection in the /vip...

Dec 10, 2025
CVE-2025-67489
9.8

CVE-2025-67489 allows remote attackers to execute arbitrary code on Vite development servers using vulnerable versions of @vitejs/plugin-rs. This affe...

Dec 9, 2025
CVE-2025-14324
9.8

A critical JIT miscompilation vulnerability in Firefox's JavaScript engine allows arbitrary code execution when processing malicious JavaScript. This ...

Dec 9, 2025
CVE-2024-32641
9.8

CVE-2024-32641 is a critical remote code execution vulnerability in Masa CMS that allows unauthenticated attackers to execute arbitrary code on affect...

Dec 3, 2025
CVE-2025-13486
EPSS 78.4% 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites running vulnerable versions of the Advanced Custom Fi...

Dec 3, 2025
CVE-2025-6389
9.8

The Sneeit Framework WordPress plugin has a critical Remote Code Execution vulnerability that allows unauthenticated attackers to execute arbitrary co...

Nov 25, 2025
CVE-2025-65099
9.8

CVE-2025-65099 is a critical code execution vulnerability in Claude Code where Yarn plugins could execute malicious code before user consent. This aff...

Nov 19, 2025
CVE-2025-12813
9.8

The Holiday Class Post Calendar WordPress plugin has a critical remote code execution vulnerability in all versions up to 7.1. Unauthenticated attacke...

Nov 11, 2025
CVE-2025-47588
9.8

This CVE-2025-47588 is a critical code injection vulnerability in the Dynamic Pricing With Discount Rules for WooCommerce plugin that allows attackers...

Nov 6, 2025
CVE-2025-32222
9.8

This CVE describes a critical code injection vulnerability in the Widget Logic WordPress plugin that allows remote code execution. Attackers can injec...

Nov 6, 2025
CVE-2025-50739
9.8

CVE-2025-50739 is a critical remote code execution vulnerability in iib0011 omni-tools v0.4.0 caused by unsafe JSON deserialization. Attackers can exe...

Oct 30, 2025
CVE-2025-62023
9.8

This CVE describes a critical remote code execution vulnerability in the s2Member WordPress plugin. Attackers can inject arbitrary code through improp...

Oct 22, 2025
CVE-2025-46581
9.8

ZTE's ZXCDN product has a critical Apache Struts vulnerability allowing unauthenticated remote code execution. Attackers can execute arbitrary command...

Oct 14, 2025
CVE-2025-59954
9.8

This vulnerability allows remote attackers to execute arbitrary code on Knowage servers by exploiting unsafe JXPathContext usage in MetaService.java. ...

Sep 30, 2025
CVE-2025-59041
9.8

CVE-2025-59041 is a critical remote code execution vulnerability in Claude Code where malicious git user.email configuration could execute arbitrary c...

Sep 10, 2025
CVE-2025-58764
9.8

CVE-2025-58764 is a command injection vulnerability in Claude Code that allows bypassing the confirmation prompt to execute untrusted commands. This a...

Sep 10, 2025
CVE-2025-57141
9.8

CVE-2025-57141 is a critical SQL injection vulnerability in rsbi-os 4.7's sqlite-jdbc component that allows remote attackers to execute arbitrary code...

Sep 8, 2025
CVE-2025-57772
9.8

This vulnerability allows remote code execution in DataEase BI tools through a JDBC URL bypass. Attackers can exploit a flaw in H2 database driver fil...

Aug 25, 2025
CVE-2025-8723
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using the Cloudflare Image Resizing plugin. All W...

Aug 19, 2025
CVE-2025-54466
9.8

This CVE describes a critical code injection vulnerability in Apache OFBiz's scrum plugin, allowing unauthenticated attackers to execute arbitrary cod...

Aug 15, 2025
CVE-2025-55346
9.8

This vulnerability allows remote attackers to execute arbitrary JavaScript code on vulnerable Flowise systems by sending specially crafted POST reques...

Aug 14, 2025
CVE-2011-10018
EPSS 53% 9.8

CVE-2011-10018 is a critical backdoor vulnerability in myBB 1.6.4 that allows unauthenticated remote attackers to execute arbitrary PHP code via manip...

Aug 13, 2025
CVE-2025-52385
9.8

This critical vulnerability in Studio 3T allows remote attackers to execute arbitrary code on affected systems by sending a crafted payload to the chi...

Aug 13, 2025
CVE-2025-50692
9.8

FoxCMS versions up to 1.2.5 contain a code injection vulnerability in the admin template file editor that allows authenticated attackers to execute ar...

Aug 7, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,145 CVEs classified as CWE-94, with 517 rated critical and 509 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free