CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,151
Total CVEs
520
Critical
512
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,151)

CVE-2024-43202
9.8

This vulnerability allows remote attackers to execute arbitrary code on Apache DolphinScheduler servers by exploiting improper input validation. It af...

Aug 20, 2024
CVE-2024-42634
9.8

This critical vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on Tenda AC9 routers. Attacker...

Aug 16, 2024
CVE-2024-41623
9.8

This vulnerability allows a local attacker to execute arbitrary code on D3D Security D3D IP Camera devices via a crafted payload. It affects D3D IP Ca...

Aug 13, 2024
CVE-2024-7094
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress servers running the JS Help Desk plugin. Attackers can ...

Aug 13, 2024
CVE-2024-36268
9.8

This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong ...

Aug 2, 2024
CVE-2024-37084
9.8

This vulnerability allows authenticated malicious users with access to the Skipper server API in Spring Cloud Data Flow to write arbitrary files anywh...

Jul 25, 2024
CVE-2024-38944
9.8

This vulnerability allows remote attackers to execute arbitrary code on Intelight X-1L traffic controllers running Maxtime version 1.9.6. Attackers ca...

Jul 22, 2024
CVE-2024-21552
9.8

CVE-2024-21552 allows arbitrary code execution on SuperAGI servers through unsafe use of the 'eval' function. Attackers can manipulate LLM outputs to ...

Jul 22, 2024
CVE-2024-39962
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-823X AX3000 routers by sending a specially crafted HTTP request to ...

Jul 19, 2024
CVE-2024-25077
9.8

This vulnerability allows attackers to modify the Nonce value in unsigned flash image headers on Renesas SmartBond devices, bypassing secureboot signa...

Jul 10, 2024
CVE-2024-39071
9.8

CVE-2024-39071 is a critical SQL injection vulnerability in Fujian Kelixun software versions up to 7.6.6.4391 that allows attackers to execute arbitra...

Jul 9, 2024
CVE-2024-6602
9.8

CVE-2024-6602 is a critical memory corruption vulnerability in Mozilla products caused by mismatched memory allocation and deallocation functions. Thi...

Jul 9, 2024
CVE-2024-38346
9.8

This critical vulnerability in Apache CloudStack allows unauthenticated attackers to execute arbitrary commands on hypervisors and management servers ...

Jul 5, 2024
CVE-2024-39165
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on systems running vulnerable versions of Asial JpGraph Profe...

Jul 4, 2024
CVE-2024-39844
9.8

This vulnerability allows remote code execution in ZNC IRC bouncer servers via the modtcl module when processing KICK commands. Attackers can execute ...

Jul 3, 2024
CVE-2024-39017
9.8

CVE-2024-39017 is a prototype pollution vulnerability in agreejs shared v0.0.1 that allows attackers to inject arbitrary properties into object protot...

Jul 1, 2024
CVE-2024-38993
9.8

CVE-2024-38993 is a prototype pollution vulnerability in rjrodger jsonic-next v2.12.1 that allows attackers to inject arbitrary properties into object...

Jul 1, 2024
CVE-2024-5826
9.8

This vulnerability allows remote attackers to execute arbitrary code on servers running vulnerable versions of vanna-ai/vanna by manipulating LLM-gene...

Jun 27, 2024
CVE-2024-5751
9.8

This vulnerability allows remote code execution in BerriAI/litellm when an attacker sends a malicious payload to the /config/update endpoint. The vuln...

Jun 27, 2024
CVE-2024-5683
9.8

This critical vulnerability in Next4Biz CRM & BPM Software allows remote attackers to inject and execute arbitrary code on affected systems. It affect...

Jun 24, 2024
CVE-2024-39331
9.8

This vulnerability in Emacs Org Mode allows arbitrary code execution when processing malicious Org documents containing specially crafted link abbrevi...

Jun 23, 2024
CVE-2024-37124
9.8

CVE-2024-37124 is a critical vulnerability in Ricoh Streamline NX PC Client that allows arbitrary file creation through dangerous function usage. Atta...

Jun 19, 2024
CVE-2024-36575
9.8

CVE-2024-36575 is a critical prototype pollution vulnerability in getsetprop 1.1.0 that allows attackers to modify JavaScript object prototypes, poten...

Jun 17, 2024
CVE-2024-38396
9.8

This vulnerability in iTerm2 allows remote code execution through malicious escape sequences in window titles when tmux integration is enabled. Attack...

Jun 16, 2024
CVE-2024-38395
9.8

This vulnerability in iTerm2 allows remote code execution when the 'Terminal may report window title' setting is not properly enforced. Attackers coul...

Jun 16, 2024
CVE-2024-37014
9.8

Langflow versions through 0.6.19 contain a remote code execution vulnerability in the custom component API endpoint. Attackers can execute arbitrary P...

Jun 10, 2024
CVE-2024-36568
9.8

CVE-2024-36568 is a critical SQL injection vulnerability in Sourcecodester Gas Agency Management System v1.0 that allows attackers to execute arbitrar...

Jun 3, 2024
CVE-2024-35339
9.8

This CVE describes a command injection vulnerability in Tenda FH1206 routers that allows remote attackers to execute arbitrary commands on the device....

May 24, 2024
CVE-2024-24294
9.8

This CVE describes a Prototype Pollution vulnerability in Blackprint's @blackprint/engine v0.9.0 that allows attackers to execute arbitrary code throu...

May 20, 2024
CVE-2024-4264
9.8

This CVE describes a critical remote code execution vulnerability in the berriai/litellm project where untrusted input is passed directly to the eval(...

May 18, 2024
CVE-2023-48643
9.8

CVE-2023-48643 allows unauthenticated remote command execution in Shrubbery tac_plus TACACS+ servers by injecting commands through authorization reque...

May 16, 2024
CVE-2024-34461
9.8

This vulnerability in Zenario CMS allows designers or administrators to execute arbitrary code through insecure Twig filter usage in the Twig Snippet ...

May 4, 2024
CVE-2024-3955
9.8

CVE-2024-3955 is a critical command injection vulnerability in CraftBeerPi 4 that allows unauthenticated remote attackers to execute arbitrary command...

May 2, 2024
CVE-2024-31822
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running the vulnerable Ecommerce-CodeIgniter-Bootstrap software. Attac...

Apr 29, 2024
CVE-2024-32491
9.8

This vulnerability allows authenticated users in Znuny and Znuny LTS to upload files to arbitrary writable locations via path traversal in manipulated...

Apr 29, 2024
CVE-2024-22632
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on affected S.I.L. 388 systems by sending a specially crafted POST reque...

Apr 26, 2024
CVE-2024-21511
9.8

CVE-2024-21511 is a critical code injection vulnerability in the mysql2 Node.js package. Attackers can execute arbitrary code by exploiting improper s...

Apr 23, 2024
CVE-2024-31666
9.8

This critical vulnerability in flusity-CMS v2.33 allows remote attackers to execute arbitrary code on affected systems by sending specially crafted sc...

Apr 22, 2024
CVE-2024-3660
9.8

This CVE describes a critical arbitrary code injection vulnerability in TensorFlow's Keras framework that allows attackers to execute arbitrary code w...

Apr 16, 2024
CVE-2024-21508
9.8

The mysql2 Node.js package before version 3.9.4 is vulnerable to remote code execution due to improper validation of configuration values. Attackers c...

Apr 11, 2024
CVE-2024-29937
9.8

This critical vulnerability in NFS implementations allows remote attackers to execute arbitrary code on affected systems without requiring authenticat...

Apr 11, 2024
CVE-2024-29500
9.8

This vulnerability in Secure Lockdown Multi Application Edition's kiosk mode allows attackers to bypass security restrictions and execute arbitrary co...

Apr 10, 2024
CVE-2024-31864
9.8

This CVE-2024-31864 is a code injection vulnerability in Apache Zeppelin that allows attackers to execute arbitrary code when connecting to MySQL data...

Apr 9, 2024
CVE-2024-31807
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK EX200 routers by sending specially crafted requests to the NTPSyncWit...

Apr 8, 2024
CVE-2024-30568
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Netgear R6850 routers by injecting malicious input into the c4-IPAddr para...

Apr 3, 2024
CVE-2024-31011
9.8

This vulnerability in BeeSCMS v4.0 allows remote attackers to write arbitrary files to the server by exploiting insufficient path isolation and lack o...

Apr 3, 2024
CVE-2024-31004
9.8

CVE-2024-31004 is a critical remote code execution vulnerability in Bento4's MP4 fragment parsing functionality. An attacker can exploit this by sendi...

Apr 2, 2024
CVE-2024-29276
9.8

This vulnerability allows remote attackers to execute arbitrary code on seeyonOA version 8 systems via the importProcess method in the WorkFlowDesigne...

Apr 2, 2024
CVE-2024-30858
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the /admin/edit_fire_wall.php endpoint in Netentsec NS-ASG 6.3. Successf...

Apr 1, 2024
CVE-2024-30868
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the /admin/add_getlogin.php endpoint in netentsec NS-ASG 6.3. Successful...

Apr 1, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,151 CVEs classified as CWE-94, with 520 rated critical and 512 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free