CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,149
Total CVEs
518
Critical
512
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,149)

CVE-2025-1302
EPSS 85.8% 9.8

CVE-2025-1302 is a critical Remote Code Execution vulnerability in jsonpath-plus versions before 10.3.0. Attackers can execute arbitrary code on affec...

Feb 15, 2025
CVE-2024-57707
9.8

This vulnerability allows remote attackers to execute arbitrary code on DataEase v1 systems by exploiting the user account and password components. At...

Feb 7, 2025
CVE-2025-22204
9.8

This vulnerability allows remote attackers to execute arbitrary code on Joomla websites using the Sourcerer extension. Attackers can exploit improper ...

Feb 4, 2025
CVE-2024-49747
9.8

This critical vulnerability in Android's Bluetooth GATT server allows remote attackers to execute arbitrary code without user interaction or elevated ...

Jan 21, 2025
CVE-2024-24421
9.8

A type confusion vulnerability in Magma's NAS message decoding function allows attackers to execute arbitrary code or cause denial of service via spec...

Jan 21, 2025
CVE-2024-42936
9.8

This vulnerability allows remote attackers to execute arbitrary code on Ruijie RG-EW300N wireless access points by sending specially crafted MQTT brok...

Jan 21, 2025
CVE-2025-22906
9.8

CVE-2025-22906 is a critical command injection vulnerability in RE11S v1.11 that allows attackers to execute arbitrary commands on affected devices by...

Jan 16, 2025
CVE-2025-22968
EPSS 41.3% 9.8

This critical vulnerability in D-Link DWR-M972V routers allows remote attackers to execute arbitrary code with root privileges via SSH without authent...

Jan 15, 2025
CVE-2023-28354
9.8

CVE-2023-28354 is a critical remote code execution vulnerability in Opsview Monitor Agent 6.8 that allows unauthenticated attackers to execute arbitra...

Jan 9, 2025
CVE-2024-11635
EPSS 18.6% 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running the vulnerable File Upload plugin. All Word...

Jan 8, 2025
CVE-2024-11613
EPSS 78.7% 9.8

This vulnerability in the WordPress File Upload plugin allows unauthenticated attackers to execute arbitrary code, read sensitive files, and delete fi...

Jan 8, 2025
CVE-2024-50660
9.8

CVE-2024-50660 is a critical file upload bypass vulnerability in AdPortal 3.0.39 that allows remote attackers to upload malicious files and execute ar...

Jan 7, 2025
CVE-2024-50658
9.8

This CVE describes a Server-Side Template Injection vulnerability in AdPortal 3.0.39 that allows remote attackers to execute arbitrary code by manipul...

Jan 7, 2025
CVE-2024-12252
EPSS 47.2% 9.8

The SEO LAT Auto Post WordPress plugin has a critical vulnerability that allows unauthenticated attackers to overwrite plugin files, which can lead to...

Jan 7, 2025
CVE-2024-56327
9.8

This vulnerability in pyrage (Python bindings for the age encryption library) allows arbitrary code execution through maliciously crafted age files. A...

Dec 19, 2024
CVE-2024-56145
9.8

CVE-2024-56145 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. Use...

Dec 18, 2024
CVE-2024-21546
9.8

This vulnerability allows attackers to execute arbitrary code on servers running vulnerable versions of the UniSharp Laravel File Manager package. By ...

Dec 18, 2024
CVE-2024-55085
9.8

GetSimple CMS CE 3.3.19 has a critical vulnerability in its template editing function that allows authenticated attackers to execute arbitrary code on...

Dec 16, 2024
CVE-2024-48453
9.8

This vulnerability allows remote attackers to execute arbitrary code on INOVANCE AM401_CPU1608TPTN programmable logic controllers via the ExecuteUserP...

Dec 4, 2024
CVE-2024-36622
9.8

CVE-2024-36622 is a command injection vulnerability in RaspAP raspap-webgui that allows attackers to execute arbitrary commands on the system by explo...

Nov 29, 2024
CVE-2024-53604
9.8

A SQL injection vulnerability in PHPGurukul COVID 19 Testing Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Nov 27, 2024
CVE-2024-52765
9.8

H3C GR-1800AX MiniGRW1B0V100R007 devices are vulnerable to remote code execution via the aspForm parameter, allowing attackers to execute arbitrary co...

Nov 20, 2024
CVE-2024-48694
9.8

This is a critical file upload vulnerability in OfficeWeb365 versions 8.6.1.0 and 7.18.23.0 that allows remote attackers to upload arbitrary files, le...

Nov 19, 2024
CVE-2024-48070
9.8

This critical vulnerability in Weaver E-cology allows unauthenticated attackers to execute arbitrary code remotely by crafting malicious requests. Att...

Nov 19, 2024
CVE-2024-50919
9.8

CVE-2024-50919 is a critical vulnerability in Jpress CMS that allows attackers to upload arbitrary files, including malicious JSP files, leading to re...

Nov 18, 2024
CVE-2024-47208
9.8

This CVE describes a Server-Side Request Forgery (SSRF) and code injection vulnerability in Apache OFBiz. Attackers can exploit it to make the server ...

Nov 18, 2024
CVE-2024-44758
9.8

This vulnerability allows attackers to upload arbitrary files to the NUS-M9 ERP Management Software via the /Production/UploadFile endpoint. Successfu...

Nov 15, 2024
CVE-2024-50636
9.8

PyMOL 2.5.0 contains a critical vulnerability in its 'Run Script' function that allows arbitrary Python code execution via malicious .PYM files. Attac...

Nov 11, 2024
CVE-2024-48050
9.8

This vulnerability allows unauthenticated remote code execution in agentscope workflow utilities. Attackers can execute arbitrary commands through the...

Nov 4, 2024
CVE-2024-48359
9.8

Qualitor v8.24 contains a critical remote code execution vulnerability via the gridValoresPopHidden parameter, allowing attackers to execute arbitrary...

Oct 31, 2024
CVE-2024-51298
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...

Oct 30, 2024
CVE-2024-8923
9.8

This is a critical input validation vulnerability in ServiceNow's Now Platform that allows unauthenticated remote code execution. All ServiceNow insta...

Oct 29, 2024
CVE-2024-48204
9.8

This SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows remote attackers to execute arbitrary SQL commands through craf...

Oct 25, 2024
CVE-2024-48514
9.8

CVE-2024-48514 is a critical code injection vulnerability in php-heic-to-jpg library versions 1.0.5 and below. Attackers can execute arbitrary code on...

Oct 24, 2024
CVE-2024-35314
9.8

This critical vulnerability in Mitel MiCollab Desktop Client and MiVoice Business SVI allows unauthenticated attackers to execute arbitrary commands t...

Oct 21, 2024
CVE-2023-26785
9.8

This CVE describes a remote code execution vulnerability in MariaDB v10.5 where an attacker could execute arbitrary code by loading a malicious shared...

Oct 17, 2024
CVE-2024-21534
9.8

CVE-2024-21534 is a critical Remote Code Execution vulnerability in jsonpath-plus package affecting all versions. Attackers can execute arbitrary code...

Oct 11, 2024
CVE-2024-45873
9.8

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code by placing a malicious DLL in the same directory a...

Oct 7, 2024
CVE-2024-46076
9.8

RuoYi v4.7.9 and earlier contains a code injection vulnerability in the code generation feature that allows attackers to escape from comments and exec...

Oct 7, 2024
CVE-2024-45186
9.8

FileSender versions before 2.49 contain a server-side template injection (SSTI) vulnerability that allows attackers to execute arbitrary code on the s...

Oct 2, 2024
CVE-2024-46640
9.8

SeaCMS 13.2 contains a remote code execution vulnerability in sql.class.chp where a security check function is bypassed during execution. Attackers ca...

Sep 20, 2024
CVE-2024-7104
9.8

This CVE describes a code injection vulnerability in SFS Consulting ww.Winsure software that allows attackers to execute arbitrary code on affected sy...

Sep 16, 2024
CVE-2024-6596
9.8

CVE-2024-6596 is a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary C# code via malicious curve...

Sep 10, 2024
CVE-2024-45507
9.8

This CVE describes a critical Server-Side Request Forgery (SSRF) and code injection vulnerability in Apache OFBiz. Attackers can exploit this to make ...

Sep 4, 2024
CVE-2024-45623
9.8

This critical vulnerability allows remote attackers to execute arbitrary code on D-Link DAP-2310 access points via a stack-based buffer overflow in th...

Sep 2, 2024
CVE-2024-41366
9.8

CVE-2024-41366 is a critical remote code execution vulnerability in RPi-Jukebox-RFID version 2.7.0 that allows attackers to execute arbitrary code on ...

Aug 29, 2024
CVE-2024-41368
9.8

CVE-2024-41368 is a critical remote code execution vulnerability in RPi-Jukebox-RFID version 2.7.0 that allows attackers to execute arbitrary code on ...

Aug 29, 2024
CVE-2024-41361
9.8

CVE-2024-41361 is a critical remote code execution vulnerability in RPi-Jukebox-RFID version 2.7.0 that allows attackers to execute arbitrary code on ...

Aug 29, 2024
CVE-2024-7720
9.8

HP Security Manager contains a critical remote code execution vulnerability (CWE-94: Code Injection) in its open-source libraries. Attackers can execu...

Aug 27, 2024
CVE-2024-40453
9.8

SquirrellyJS template engine versions 9.0.0 contain a code injection vulnerability in the options.varName component that allows attackers to execute a...

Aug 21, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,149 CVEs classified as CWE-94, with 518 rated critical and 512 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free