CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,147
Total CVEs
517
Critical
511
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,147)

CVE-2025-50706
9.8

This vulnerability in ThinkPHP v5.1 allows remote attackers to execute arbitrary code via the routecheck function due to improper input validation. It...

Aug 5, 2025
CVE-2025-51387
9.8

CVE-2025-51387 allows remote code execution in GitKraken Desktop due to misconfigured Electron Fuses. Attackers can execute arbitrary code by passing ...

Aug 4, 2025
CVE-2025-46059
9.8

LangChain v0.3.51 contains an indirect prompt injection vulnerability in the GmailToolkit component that allows attackers to execute arbitrary code vi...

Jul 29, 2025
CVE-2025-54451
9.8

This CVE describes a code injection vulnerability in Samsung MagicINFO 9 Server that allows attackers to execute arbitrary code on affected systems. T...

Jul 23, 2025
CVE-2025-54068
EPSS 22% 9.8

This vulnerability in Livewire v3 allows unauthenticated attackers to execute arbitrary commands remotely on affected systems. The issue occurs when s...

Jul 17, 2025
CVE-2025-53867
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Island Lake WebBatch by sending a speci...

Jul 17, 2025
CVE-2025-5396
9.8

The Bears Backup plugin for WordPress has a critical Remote Code Execution vulnerability that allows unauthenticated attackers to execute arbitrary co...

Jul 17, 2025
CVE-2025-53890
9.8

An unsafe JavaScript evaluation vulnerability in pyLoad's CAPTCHA processing allows unauthenticated remote attackers to execute arbitrary code in clie...

Jul 15, 2025
CVE-2025-5392
9.8

The GB Forms DB WordPress plugin has a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code on...

Jul 11, 2025
CVE-2025-45479
9.8

This vulnerability allows attackers to execute arbitrary code on educoder challenge containers by injecting malicious content. It affects all users of...

Jul 7, 2025
CVE-2025-37099
9.8

A critical remote code execution vulnerability exists in HPE Insight Remote Support (IRS) software due to improper control of code generation (CWE-94)...

Jul 1, 2025
CVE-2023-47030
9.8

CVE-2023-47030 is a critical remote code execution vulnerability in NCR Terminal Handler v1.5.1 that allows unauthenticated attackers to execute arbit...

Jun 23, 2025
CVE-2023-47032
9.8

CVE-2023-47032 is a critical remote code execution vulnerability in NCR Terminal Handler v1.5.1 that allows attackers to execute arbitrary code via cr...

Jun 23, 2025
CVE-2023-48978
9.8

This vulnerability allows remote attackers to execute arbitrary code on NCR ITM Web terminal systems by sending crafted scripts to the IP camera URL c...

Jun 23, 2025
CVE-2025-32798
9.8

CVE-2025-32798 allows arbitrary code execution during conda package builds due to unsafe eval() usage in recipe selectors. Attackers can inject malici...

Jun 16, 2025
CVE-2025-5309
9.8

A Server-Side Template Injection vulnerability in BeyondTrust's Remote Support and Privileged Remote Access chat feature allows attackers to execute a...

Jun 16, 2025
CVE-2025-44881
9.8

This CVE describes a critical command injection vulnerability in the Wavlink WL-WN579A3 router's QoS configuration interface. Attackers can execute ar...

May 20, 2025
CVE-2025-46724
9.8

This vulnerability allows remote code execution through code injection in Langroid's TableChatAgent when processing untrusted user input. It affects a...

May 20, 2025
CVE-2025-32363
9.8

CVE-2025-32363 is a critical remote code execution vulnerability in mediDOK software versions before 2.5.18.43. Attackers can exploit insecure deseria...

May 14, 2025
CVE-2024-24780
9.8

This vulnerability allows attackers with UDF creation privileges in Apache IoTDB to execute arbitrary code by registering malicious functions from unt...

May 14, 2025
CVE-2025-44022
9.8

This vulnerability in Vvveb CMS v1.0.6 allows remote attackers to execute arbitrary code through the plugin mechanism. Attackers can upload malicious ...

May 12, 2025
CVE-2025-26845
9.8

CVE-2025-26845 is an eval injection vulnerability in Znuny that allows authenticated users with configuration write access to execute arbitrary comman...

May 8, 2025
CVE-2025-44071
9.8

SeaCMS v13.3 contains a remote code execution vulnerability in phomebak.php that allows attackers to execute arbitrary code via crafted HTTP requests....

May 5, 2025
CVE-2025-2421
9.8

This critical code injection vulnerability in Profelis Informatics SambaBox allows attackers to execute arbitrary code on affected systems. All SambaB...

May 2, 2025
CVE-2025-45947
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running phpgurukul Online Banquet Booking System V1.2. Attackers can e...

Apr 28, 2025
CVE-2024-40446
9.8

This vulnerability in forkosh Mime Tex allows remote attackers to execute arbitrary code via specially crafted scripts. It affects all users running v...

Apr 22, 2025
CVE-2024-53924
9.8

Pycel versions up to 1.0b30 allow remote code execution when processing untrusted Excel spreadsheets containing malicious formulas. Attackers can craf...

Apr 17, 2025
CVE-2025-29662
9.8

CVE-2025-29662 is a critical remote code execution vulnerability in LandChat 3.25.12.18 that allows unauthenticated attackers to execute arbitrary sys...

Apr 17, 2025
CVE-2024-56518
9.8

CVE-2024-56518 allows remote attackers to execute arbitrary code on Hazelcast Management Center servers by uploading a malicious hazelcast-client XML ...

Apr 17, 2025
CVE-2025-3115
9.8

CVE-2025-3115 is a critical vulnerability in Spotfire software that allows attackers to inject malicious code and upload malicious files due to insuff...

Apr 9, 2025
CVE-2025-28146
EPSS 17.5% 9.8

This CVE describes a critical command injection vulnerability in Edimax AC1200 routers that allows attackers to execute arbitrary commands on the devi...

Apr 4, 2025
CVE-2024-13645
9.8

The tagDiv Composer WordPress plugin has a PHP object instantiation vulnerability that allows unauthenticated attackers to instantiate arbitrary PHP o...

Apr 4, 2025
CVE-2025-29064
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X18 routers via the cstecgi.cgi interface. Attac...

Apr 3, 2025
CVE-2024-54804
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Netgear WNR854T routers by sending a specially crafted request to post.cgi...

Mar 31, 2025
CVE-2024-54806
9.8

CVE-2024-54806 allows remote attackers to execute arbitrary system commands on Netgear WNR854T routers through the cmd.cgi web interface. This affects...

Mar 31, 2025
CVE-2025-29306
EPSS 85.3% 9.8

This vulnerability allows remote attackers to execute arbitrary code on FoxCMS v1.2.5 systems through the case display page in index.html. It affects ...

Mar 27, 2025
CVE-2024-55964
EPSS 67.3% 9.8

This vulnerability allows authenticated attackers to execute arbitrary commands within Appsmith Docker containers by exploiting a misconfigured Postgr...

Mar 26, 2025
CVE-2024-48818
9.8

This critical vulnerability in IIT Bombay's Bodhitree cs101 platform allows remote attackers to execute arbitrary code on affected systems. It affects...

Mar 25, 2025
CVE-2024-57061
9.8

This vulnerability allows a physically proximate attacker to execute arbitrary code on Termius installations due to insufficient Electron Fuses config...

Mar 19, 2025
CVE-2025-1550
9.8

CVE-2025-1550 is a critical remote code execution vulnerability in Keras where the Model.load_model function can execute arbitrary Python code even wi...

Mar 11, 2025
CVE-2025-1497
9.8

CVE-2025-1497 is a critical remote code execution vulnerability in PlotAI where insufficient validation of LLM-generated output allows attackers to ex...

Mar 10, 2025
CVE-2024-42733
9.8

CVE-2024-42733 is a critical remote code execution vulnerability in Docmosis Tornado document generation software. It allows attackers to execute arbi...

Mar 7, 2025
CVE-2025-25362
9.8

This Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code by injecting malicious payload...

Mar 5, 2025
CVE-2025-27657
9.8

This critical vulnerability in Vasion Print (formerly PrinterLogic) allows remote attackers to execute arbitrary code on affected systems without auth...

Mar 5, 2025
CVE-2024-53944
9.8

This CVE describes a critical command injection vulnerability in Tuoshi/Dionlink 4G Wi-Fi devices. Unauthenticated remote attackers can execute arbitr...

Feb 27, 2025
CVE-2025-25789
9.8

FoxCMS v1.2.5 contains a critical remote code execution vulnerability in the index() method of the Sitemap controller. This allows unauthenticated att...

Feb 26, 2025
CVE-2025-26014
9.8

A critical Remote Code Execution vulnerability in Loggrove v1.0 allows attackers to execute arbitrary code on affected systems by manipulating the pat...

Feb 21, 2025
CVE-2024-54756
9.8

This CVE describes a critical remote code execution vulnerability in GZDoom v4.13.1. Attackers can exploit it by tricking users into opening a malicio...

Feb 20, 2025
CVE-2024-57401
9.8

A critical SQL injection vulnerability in Uniclare Student Portal versions 2 and earlier allows remote attackers to execute arbitrary SQL commands thr...

Feb 20, 2025
CVE-2025-25467
9.8

This critical memory management vulnerability in libx264 allows attackers to execute arbitrary code by processing a specially crafted AAC file. Any ap...

Feb 18, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,147 CVEs classified as CWE-94, with 517 rated critical and 511 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free