CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,151)
This vulnerability allows remote attackers to execute arbitrary code on Apache DolphinScheduler servers by exploiting improper input validation. It af...
Aug 20, 2024This critical vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on Tenda AC9 routers. Attacker...
Aug 16, 2024This vulnerability allows a local attacker to execute arbitrary code on D3D Security D3D IP Camera devices via a crafted payload. It affects D3D IP Ca...
Aug 13, 2024This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress servers running the JS Help Desk plugin. Attackers can ...
Aug 13, 2024This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong ...
Aug 2, 2024This vulnerability allows authenticated malicious users with access to the Skipper server API in Spring Cloud Data Flow to write arbitrary files anywh...
Jul 25, 2024This vulnerability allows remote attackers to execute arbitrary code on Intelight X-1L traffic controllers running Maxtime version 1.9.6. Attackers ca...
Jul 22, 2024CVE-2024-21552 allows arbitrary code execution on SuperAGI servers through unsafe use of the 'eval' function. Attackers can manipulate LLM outputs to ...
Jul 22, 2024This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-823X AX3000 routers by sending a specially crafted HTTP request to ...
Jul 19, 2024This vulnerability allows attackers to modify the Nonce value in unsigned flash image headers on Renesas SmartBond devices, bypassing secureboot signa...
Jul 10, 2024CVE-2024-39071 is a critical SQL injection vulnerability in Fujian Kelixun software versions up to 7.6.6.4391 that allows attackers to execute arbitra...
Jul 9, 2024CVE-2024-6602 is a critical memory corruption vulnerability in Mozilla products caused by mismatched memory allocation and deallocation functions. Thi...
Jul 9, 2024This critical vulnerability in Apache CloudStack allows unauthenticated attackers to execute arbitrary commands on hypervisors and management servers ...
Jul 5, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on systems running vulnerable versions of Asial JpGraph Profe...
Jul 4, 2024This vulnerability allows remote code execution in ZNC IRC bouncer servers via the modtcl module when processing KICK commands. Attackers can execute ...
Jul 3, 2024CVE-2024-39017 is a prototype pollution vulnerability in agreejs shared v0.0.1 that allows attackers to inject arbitrary properties into object protot...
Jul 1, 2024CVE-2024-38993 is a prototype pollution vulnerability in rjrodger jsonic-next v2.12.1 that allows attackers to inject arbitrary properties into object...
Jul 1, 2024This vulnerability allows remote attackers to execute arbitrary code on servers running vulnerable versions of vanna-ai/vanna by manipulating LLM-gene...
Jun 27, 2024This vulnerability allows remote code execution in BerriAI/litellm when an attacker sends a malicious payload to the /config/update endpoint. The vuln...
Jun 27, 2024This critical vulnerability in Next4Biz CRM & BPM Software allows remote attackers to inject and execute arbitrary code on affected systems. It affect...
Jun 24, 2024This vulnerability in Emacs Org Mode allows arbitrary code execution when processing malicious Org documents containing specially crafted link abbrevi...
Jun 23, 2024CVE-2024-37124 is a critical vulnerability in Ricoh Streamline NX PC Client that allows arbitrary file creation through dangerous function usage. Atta...
Jun 19, 2024CVE-2024-36575 is a critical prototype pollution vulnerability in getsetprop 1.1.0 that allows attackers to modify JavaScript object prototypes, poten...
Jun 17, 2024This vulnerability in iTerm2 allows remote code execution through malicious escape sequences in window titles when tmux integration is enabled. Attack...
Jun 16, 2024This vulnerability in iTerm2 allows remote code execution when the 'Terminal may report window title' setting is not properly enforced. Attackers coul...
Jun 16, 2024Langflow versions through 0.6.19 contain a remote code execution vulnerability in the custom component API endpoint. Attackers can execute arbitrary P...
Jun 10, 2024CVE-2024-36568 is a critical SQL injection vulnerability in Sourcecodester Gas Agency Management System v1.0 that allows attackers to execute arbitrar...
Jun 3, 2024This CVE describes a command injection vulnerability in Tenda FH1206 routers that allows remote attackers to execute arbitrary commands on the device....
May 24, 2024This CVE describes a Prototype Pollution vulnerability in Blackprint's @blackprint/engine v0.9.0 that allows attackers to execute arbitrary code throu...
May 20, 2024This CVE describes a critical remote code execution vulnerability in the berriai/litellm project where untrusted input is passed directly to the eval(...
May 18, 2024CVE-2023-48643 allows unauthenticated remote command execution in Shrubbery tac_plus TACACS+ servers by injecting commands through authorization reque...
May 16, 2024This vulnerability in Zenario CMS allows designers or administrators to execute arbitrary code through insecure Twig filter usage in the Twig Snippet ...
May 4, 2024CVE-2024-3955 is a critical command injection vulnerability in CraftBeerPi 4 that allows unauthenticated remote attackers to execute arbitrary command...
May 2, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running the vulnerable Ecommerce-CodeIgniter-Bootstrap software. Attac...
Apr 29, 2024This vulnerability allows authenticated users in Znuny and Znuny LTS to upload files to arbitrary writable locations via path traversal in manipulated...
Apr 29, 2024This vulnerability allows unauthenticated attackers to execute arbitrary code on affected S.I.L. 388 systems by sending a specially crafted POST reque...
Apr 26, 2024CVE-2024-21511 is a critical code injection vulnerability in the mysql2 Node.js package. Attackers can execute arbitrary code by exploiting improper s...
Apr 23, 2024This critical vulnerability in flusity-CMS v2.33 allows remote attackers to execute arbitrary code on affected systems by sending specially crafted sc...
Apr 22, 2024This CVE describes a critical arbitrary code injection vulnerability in TensorFlow's Keras framework that allows attackers to execute arbitrary code w...
Apr 16, 2024The mysql2 Node.js package before version 3.9.4 is vulnerable to remote code execution due to improper validation of configuration values. Attackers c...
Apr 11, 2024This critical vulnerability in NFS implementations allows remote attackers to execute arbitrary code on affected systems without requiring authenticat...
Apr 11, 2024This vulnerability in Secure Lockdown Multi Application Edition's kiosk mode allows attackers to bypass security restrictions and execute arbitrary co...
Apr 10, 2024This CVE-2024-31864 is a code injection vulnerability in Apache Zeppelin that allows attackers to execute arbitrary code when connecting to MySQL data...
Apr 9, 2024This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK EX200 routers by sending specially crafted requests to the NTPSyncWit...
Apr 8, 2024This vulnerability allows remote attackers to execute arbitrary commands on Netgear R6850 routers by injecting malicious input into the c4-IPAddr para...
Apr 3, 2024This vulnerability in BeeSCMS v4.0 allows remote attackers to write arbitrary files to the server by exploiting insufficient path isolation and lack o...
Apr 3, 2024CVE-2024-31004 is a critical remote code execution vulnerability in Bento4's MP4 fragment parsing functionality. An attacker can exploit this by sendi...
Apr 2, 2024This vulnerability allows remote attackers to execute arbitrary code on seeyonOA version 8 systems via the importProcess method in the WorkFlowDesigne...
Apr 2, 2024This vulnerability allows attackers to execute arbitrary SQL commands through the /admin/edit_fire_wall.php endpoint in Netentsec NS-ASG 6.3. Successf...
Apr 1, 2024This vulnerability allows attackers to execute arbitrary SQL commands through the /admin/add_getlogin.php endpoint in netentsec NS-ASG 6.3. Successful...
Apr 1, 2024About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,151 CVEs classified as CWE-94, with 520 rated critical and 512 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free