CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,145)
This vulnerability allows remote code execution by exploiting improper input sanitization in industrial controllers. Attackers can inject malicious co...
Oct 27, 2021This vulnerability allows authorized users in SAP Commerce Backoffice to inject malicious code into source rules, which are translated to Drools rules...
Apr 13, 2021CVE-2021-21433 is a critical remote code execution vulnerability in Discord Recon Server version 0.0.1, allowing attackers to execute arbitrary comman...
Apr 9, 2021This vulnerability in Langflow's CSV Agent node allows attackers to execute arbitrary Python and OS commands on the server via prompt injection, leadi...
Feb 26, 2026The SPIP tickets plugin contains an unauthenticated remote code execution vulnerability in forum preview handling. Attackers can inject malicious cont...
Feb 25, 2026The Saisies plugin for SPIP contains a critical Remote Code Execution vulnerability (CWE-94: Improper Control of Generation of Code) that allows attac...
Feb 19, 2026CVE-2026-27174 allows unauthenticated attackers to execute arbitrary PHP code on MajorDoMo home automation systems via the admin panel's PHP console. ...
Feb 18, 2026CVE-2020-37186 is a critical remote code execution vulnerability in Chevereto image hosting software. Attackers can inject malicious PHP code during d...
Feb 11, 2026This vulnerability in DiskCache (python-diskcache) allows arbitrary code execution when an attacker with write access to the cache directory injects m...
Feb 11, 2026The jsonpath package is vulnerable to arbitrary code execution via malicious JSON Path expressions. Attackers can inject JavaScript code that gets exe...
Feb 9, 2026CVE-2025-69983 is a critical remote code execution vulnerability in FUXA v1.2.7 that allows attackers to execute arbitrary system commands through mal...
Feb 3, 2026This CVE describes a code injection vulnerability in Orval, a tool that generates TypeScript clients from OpenAPI/Swagger specifications. The incomple...
Jan 30, 2026This critical vulnerability in Ivanti Endpoint Manager Mobile allows unauthenticated attackers to inject malicious code and execute arbitrary commands...
Jan 29, 2026CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to execute arb...
Jan 29, 2026CVE-2025-69564 is a critical SQL injection vulnerability in code-projects Mobile Shop Management System 1.0 that allows attackers to execute arbitrary...
Jan 27, 2026This vulnerability in vm2 sandbox for Node.js allows attackers to bypass Promise callback sanitization and escape the sandbox environment. Attackers c...
Jan 26, 2026CVE-2026-0768 is a critical remote code execution vulnerability in Langflow that allows unauthenticated attackers to execute arbitrary Python code on ...
Jan 23, 2026This critical vulnerability allows unauthenticated remote attackers to execute arbitrary Python code on systems running vulnerable versions of Foundat...
Jan 23, 2026A critical command injection vulnerability in ipTIME routers allows attackers to execute arbitrary operating system commands by injecting malicious in...
Jan 20, 2026This critical vulnerability in Malware Remover allows remote attackers to bypass security protections through improper code generation control. Attack...
Jan 2, 2026This vulnerability allows unauthenticated attackers to execute arbitrary commands remotely on affected JD Cloud NAS routers. Attackers can gain full c...
Dec 30, 2025Eigent multi-agent Workforce version 0.0.60 contains a 1-click Remote Code Execution vulnerability that allows attackers to execute arbitrary code on ...
Dec 27, 2025This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running the Print Invoice & Delivery Notes for WooC...
Dec 24, 2025Insecure permissions in MineAdmin v3.x scheduled tasks allow attackers to execute arbitrary commands, leading to remote code execution and full accoun...
Dec 12, 2025This CVE describes a GitHub Actions workflow vulnerability in Parse Server that grants elevated permissions to CI/CD pipelines. It allows unauthorized...
Dec 12, 2025Aqara Hub devices contain an undocumented remote access mechanism that allows attackers to execute arbitrary commands without authentication. This vul...
Dec 10, 2025An unauthenticated remote code execution vulnerability in ChanCMS v3.3.4 allows attackers to execute arbitrary code via template injection in the /vip...
Dec 10, 2025CVE-2025-67489 allows remote attackers to execute arbitrary code on Vite development servers using vulnerable versions of @vitejs/plugin-rs. This affe...
Dec 9, 2025A critical JIT miscompilation vulnerability in Firefox's JavaScript engine allows arbitrary code execution when processing malicious JavaScript. This ...
Dec 9, 2025CVE-2024-32641 is a critical remote code execution vulnerability in Masa CMS that allows unauthenticated attackers to execute arbitrary code on affect...
Dec 3, 2025This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites running vulnerable versions of the Advanced Custom Fi...
Dec 3, 2025The Sneeit Framework WordPress plugin has a critical Remote Code Execution vulnerability that allows unauthenticated attackers to execute arbitrary co...
Nov 25, 2025CVE-2025-65099 is a critical code execution vulnerability in Claude Code where Yarn plugins could execute malicious code before user consent. This aff...
Nov 19, 2025The Holiday Class Post Calendar WordPress plugin has a critical remote code execution vulnerability in all versions up to 7.1. Unauthenticated attacke...
Nov 11, 2025This CVE-2025-47588 is a critical code injection vulnerability in the Dynamic Pricing With Discount Rules for WooCommerce plugin that allows attackers...
Nov 6, 2025This CVE describes a critical code injection vulnerability in the Widget Logic WordPress plugin that allows remote code execution. Attackers can injec...
Nov 6, 2025CVE-2025-50739 is a critical remote code execution vulnerability in iib0011 omni-tools v0.4.0 caused by unsafe JSON deserialization. Attackers can exe...
Oct 30, 2025This CVE describes a critical remote code execution vulnerability in the s2Member WordPress plugin. Attackers can inject arbitrary code through improp...
Oct 22, 2025ZTE's ZXCDN product has a critical Apache Struts vulnerability allowing unauthenticated remote code execution. Attackers can execute arbitrary command...
Oct 14, 2025This vulnerability allows remote attackers to execute arbitrary code on Knowage servers by exploiting unsafe JXPathContext usage in MetaService.java. ...
Sep 30, 2025CVE-2025-59041 is a critical remote code execution vulnerability in Claude Code where malicious git user.email configuration could execute arbitrary c...
Sep 10, 2025CVE-2025-58764 is a command injection vulnerability in Claude Code that allows bypassing the confirmation prompt to execute untrusted commands. This a...
Sep 10, 2025CVE-2025-57141 is a critical SQL injection vulnerability in rsbi-os 4.7's sqlite-jdbc component that allows remote attackers to execute arbitrary code...
Sep 8, 2025This vulnerability allows remote code execution in DataEase BI tools through a JDBC URL bypass. Attackers can exploit a flaw in H2 database driver fil...
Aug 25, 2025This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using the Cloudflare Image Resizing plugin. All W...
Aug 19, 2025This CVE describes a critical code injection vulnerability in Apache OFBiz's scrum plugin, allowing unauthenticated attackers to execute arbitrary cod...
Aug 15, 2025This vulnerability allows remote attackers to execute arbitrary JavaScript code on vulnerable Flowise systems by sending specially crafted POST reques...
Aug 14, 2025CVE-2011-10018 is a critical backdoor vulnerability in myBB 1.6.4 that allows unauthenticated remote attackers to execute arbitrary PHP code via manip...
Aug 13, 2025This critical vulnerability in Studio 3T allows remote attackers to execute arbitrary code on affected systems by sending a crafted payload to the chi...
Aug 13, 2025FoxCMS versions up to 1.2.5 contain a code injection vulnerability in the admin template file editor that allows authenticated attackers to execute ar...
Aug 7, 2025About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,145 CVEs classified as CWE-94, with 517 rated critical and 509 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free