CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,151
Total CVEs
520
Critical
512
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,151)

CVE-2024-31032
9.8

This vulnerability allows remote attackers to execute arbitrary code on Huashi Private Cloud CDN Live Streaming Acceleration Server via the manager/ip...

Mar 29, 2024
CVE-2024-28386
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running fastmagsync v1.7.51 and earlier. Attackers can exploit the get...

Mar 25, 2024
CVE-2023-41503
9.8

CVE-2023-41503 is a critical SQL injection vulnerability in Student Enrollment In PHP v1.0 that allows attackers to execute arbitrary SQL commands thr...

Mar 7, 2024
CVE-2024-0917
9.8

CVE-2024-0917 is a critical remote code execution vulnerability in PaddlePaddle 2.6.0 due to improper input validation (CWE-94). Attackers can execute...

Mar 7, 2024
CVE-2024-25180
9.8

CVE-2024-25180 is a disputed vulnerability in pdfmake 0.2.9 where a crafted POST request to the /pdf endpoint could allow remote code execution. The v...

Feb 29, 2024
CVE-2024-25291
9.8

CVE-2024-25291 is a critical remote code execution vulnerability in Deskfiler v1.2.3 that allows attackers to execute arbitrary code by uploading a ma...

Feb 29, 2024
CVE-2024-24525
9.8

A critical remote code execution vulnerability in EpointWebBuilder allows attackers to execute arbitrary code via the infoid parameter. This affects a...

Feb 29, 2024
CVE-2023-51801
9.8

This SQL injection vulnerability in Simple Student Attendance System v1.0 allows remote attackers to execute arbitrary SQL commands via the id paramet...

Feb 29, 2024
CVE-2024-25350
9.8

This CVE describes a critical SQL injection vulnerability in the Zoo Management System 1.0 by PHPGurukul. Attackers can inject malicious SQL commands ...

Feb 28, 2024
CVE-2024-22988
9.8

This vulnerability in ZKteco ZKBio WDMS allows attackers to download database backups by predicting timestamp-based filenames in the /files/backup/ co...

Feb 23, 2024
CVE-2024-25249
9.8

This vulnerability in He3 App for macOS allows remote attackers to execute arbitrary code by exploiting misconfigured Electron settings (RunAsNode and...

Feb 21, 2024
CVE-2023-49109
9.8

This vulnerability allows remote attackers to execute arbitrary code on Apache DolphinScheduler servers due to improper input validation (CWE-94). It ...

Feb 20, 2024
CVE-2023-52381
9.8

This CVE describes a script injection vulnerability in Huawei's email module that allows attackers to execute arbitrary code. Successful exploitation ...

Feb 18, 2024
CVE-2024-25502
9.8

CVE-2024-25502 is a critical directory traversal vulnerability in flusity CMS v2.4 that allows remote attackers to execute arbitrary code and access s...

Feb 15, 2024
CVE-2022-23088
9.8

This vulnerability allows remote attackers to execute arbitrary code on FreeBSD systems by sending specially crafted 802.11 beacon frames with malicio...

Feb 15, 2024
CVE-2023-42374
9.8

A critical vulnerability in Sui Blockchain nodes before version 1.6.3 allows remote attackers to execute arbitrary code and cause denial of service by...

Feb 13, 2024
CVE-2024-25089
9.8

This vulnerability in Malwarebytes Binisoft Windows Firewall Control allows remote attackers to execute arbitrary code via gRPC named pipes. Attackers...

Feb 4, 2024
CVE-2023-50488
9.8

This vulnerability allows remote attackers to execute arbitrary code on Blurams Lumi Security Camera (A31C) devices. Attackers can exploit improper in...

Feb 2, 2024
CVE-2024-23746
9.8

CVE-2024-23746 is a local privilege escalation vulnerability in Miro Desktop for macOS that allows attackers to inject malicious code into the Electro...

Feb 2, 2024
CVE-2024-1015
9.8

A critical remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 devices allows attackers to execute arbitrary operating system comman...

Jan 29, 2024
CVE-2024-23742
9.8

This vulnerability in Loom on macOS allows remote attackers to execute arbitrary code by exploiting the RunAsNode and enableNodeCliInspectArguments se...

Jan 28, 2024
CVE-2023-36177
9.8

A critical vulnerability in Snapcast 0.27.0 allows remote attackers to execute arbitrary code and access sensitive information through crafted JSON-RP...

Jan 23, 2024
CVE-2022-1609
9.8

CVE-2022-1609 is a critical remote code execution vulnerability in the School Management WordPress plugin. Unauthenticated attackers can execute arbit...

Jan 16, 2024
CVE-2023-46226
9.8

CVE-2023-46226 is a critical remote code execution vulnerability in Apache IoTDB that allows attackers to execute arbitrary code on affected systems. ...

Jan 15, 2024
CVE-2023-51784
9.8

This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong ...

Jan 3, 2024
CVE-2023-41544
9.8

This is a Server-Side Template Injection (SSTI) vulnerability in jeecg-boot version 3.5.3 that allows remote attackers to execute arbitrary code via c...

Dec 30, 2023
CVE-2023-49000
9.8

This vulnerability in ArtistScope ArtisBrowser allows attackers to bypass access restrictions by exploiting the com.artis.browser.IntentReceiverActivi...

Dec 27, 2023
CVE-2023-47883
9.8

This vulnerability allows remote code execution in the TV Browser Android app through JavaScript injection via an exposed MainActivity. Attackers can ...

Dec 27, 2023
CVE-2023-43481
9.8

This vulnerability allows remote attackers to execute arbitrary JavaScript code in the TCL Browser TV Web BrowseHere application. Attackers can exploi...

Dec 27, 2023
CVE-2023-49032
9.8

CVE-2023-49032 is a critical vulnerability in LTB Self Service Password that allows remote attackers to hijack SMS verification codes and send them to...

Dec 21, 2023
CVE-2023-48390
9.8

Multisuns EasyLog web+ has a critical code injection vulnerability (CWE-94) that allows unauthenticated remote attackers to execute arbitrary code on ...

Dec 15, 2023
CVE-2023-49070
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Apache OFBiz servers by exploiting a deprecated XML-RPC compon...

Dec 5, 2023
CVE-2023-49093
9.8

HtmlUnit versions before 3.9.0 are vulnerable to remote code execution when processing malicious webpages containing XSLT transformations. This allows...

Dec 4, 2023
CVE-2023-49313
9.8

This CVE describes a dylib injection vulnerability in XMachOViewer that allows attackers to inject malicious dynamic libraries into the application's ...

Nov 28, 2023
CVE-2023-5604
9.8

The Asgaros Forum WordPress plugin before version 2.7.1 allows forum administrators (who may not have full WordPress admin privileges) to configure in...

Nov 27, 2023
CVE-2023-6016
9.8

CVE-2023-6016 allows remote attackers to execute arbitrary code on H2O dashboard servers through insecure deserialization in the POJO model import fea...

Nov 16, 2023
CVE-2023-47397
9.8

CVE-2023-47397 is a critical code injection vulnerability in WeBid auction software that allows attackers to execute arbitrary code on affected system...

Nov 8, 2023
CVE-2023-46980
9.8

This vulnerability in Best Courier Management System v1.0 allows remote attackers to execute arbitrary code and escalate privileges by sending a craft...

Nov 3, 2023
CVE-2023-46958
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running lmxcms v1.41 by sending crafted scripts to the admin.php file....

Nov 2, 2023
CVE-2023-46509
9.8

This vulnerability allows remote attackers to execute arbitrary code on Contec SolarView Compact devices via the texteditor.php component. It affects ...

Oct 27, 2023
CVE-2023-46010
9.8

This vulnerability in SeaCMS v12.9 allows remote attackers to execute arbitrary commands through the admin_safe.php component. This is a critical remo...

Oct 25, 2023
CVE-2023-30131
9.8

This vulnerability in IXP EasyInstall 6.6.14884.0 allows unauthenticated attackers to execute arbitrary commands on affected systems via API calls. At...

Oct 19, 2023
CVE-2023-46042
9.8

This vulnerability in GetSimpleCMS v3.4.0a allows remote attackers to execute arbitrary code via a crafted payload to phpinfo(). Attackers can achieve...

Oct 19, 2023
CVE-2023-41630
9.8

CVE-2023-41630 is a critical remote code execution vulnerability in eSST Monitoring v2.147.1 that allows unauthenticated attackers to execute arbitrar...

Oct 17, 2023
CVE-2023-29453
9.8

CVE-2023-29453 is a critical template injection vulnerability in Go's html/template package that allows attackers to inject arbitrary JavaScript code ...

Oct 12, 2023
CVE-2023-43625
9.8

CVE-2023-43625 is a critical remote code execution vulnerability in Simcenter Amesim's SOAP endpoint. Unauthenticated remote attackers can perform DLL...

Oct 10, 2023
CVE-2023-45311
9.8

This CVE describes a supply chain vulnerability in fsevents where versions before 1.2.11 fetched binaries from an external URL that could be compromis...

Oct 6, 2023
CVE-2023-3656
9.8

CVE-2023-3656 is an unauthenticated remote code execution vulnerability in cashIT! devices from PoS/Dienstleistung, Entwicklung & Vertrieb GmbH. Attac...

Oct 3, 2023
CVE-2023-43234
9.8

DedeBIZ v6.2.11 contains critical remote code execution vulnerabilities in the file management admin interface. Attackers can execute arbitrary code o...

Sep 27, 2023
CVE-2021-38243
9.8

XunruiCMS up to version 4.5.1 contains a remote code execution vulnerability in index.php that allows attackers to execute arbitrary code via crafted ...

Sep 27, 2023

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,151 CVEs classified as CWE-94, with 520 rated critical and 512 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free