CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,153
Total CVEs
521
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Moodle 7
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,153)

CVE-2023-4291
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code on Frauscher Sensortechnik FDS101 devices by sending manipulate...

Sep 21, 2023
CVE-2023-42470
9.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices running the Imou Life app (com.mm.android.smartlifeiot) by sen...

Sep 11, 2023
CVE-2023-39320
9.8

CVE-2023-39320 is a critical vulnerability in Go's module system that allows arbitrary code execution when processing malicious go.mod files. It affec...

Sep 8, 2023
CVE-2023-39681
9.8

Cuppa CMS v1.0 contains a critical remote code execution vulnerability in the email_outgoing parameter at /Configuration.php. Attackers can execute ar...

Sep 5, 2023
CVE-2023-39631
9.8

This vulnerability allows remote attackers to execute arbitrary code through the evaluate function in LangChain's numexpr library integration. It affe...

Sep 1, 2023
CVE-2023-36281
9.8

This vulnerability in LangChain versions before 0.0.312 allows remote attackers to execute arbitrary code by loading a malicious JSON file containing ...

Aug 22, 2023
CVE-2023-39660
9.8

This vulnerability in pandasai allows remote attackers to execute arbitrary code by sending specially crafted requests to the prompt function. It affe...

Aug 21, 2023
CVE-2023-31447
9.8

This vulnerability allows attackers to send crafted payloads to the user_login.cgi endpoint on affected Draytek Vigor devices, enabling arbitrary code...

Aug 21, 2023
CVE-2023-32626
9.8

This vulnerability allows unauthenticated attackers to access hidden management functionality in affected ELECOM wireless LAN routers, enabling them t...

Aug 18, 2023
CVE-2023-38860
9.8

This vulnerability in LangChain allows remote attackers to execute arbitrary code by manipulating the prompt parameter. It affects all systems running...

Aug 15, 2023
CVE-2023-36095
9.8

This vulnerability in LangChain version 0.0.194 allows remote code execution through unsafe Python exec() calls in PALChain functions. Attackers can e...

Aug 5, 2023
CVE-2023-34842
9.8

This critical vulnerability in DedeCMS allows remote attackers to execute arbitrary code on affected systems by sending specially crafted POST request...

Jul 31, 2023
CVE-2023-39017
9.8

CVE-2023-39017 is a code injection vulnerability in quartz-jobs 2.3.2 and earlier that could allow remote code execution via the SendQueueMessageJob.e...

Jul 28, 2023
CVE-2023-39020
9.8

CVE-2023-39020 is a critical code injection vulnerability in Stanford Parser versions 3.9.2 and below that allows remote attackers to execute arbitrar...

Jul 28, 2023
CVE-2023-39022
9.8

CVE-2023-39022 is a critical code injection vulnerability in oscore v2.2.6 and earlier that allows remote attackers to execute arbitrary code by passi...

Jul 28, 2023
CVE-2023-39010
9.8

BoofCV 0.42 contains a code injection vulnerability in the camera calibration file loading component. Attackers can execute arbitrary code by tricking...

Jul 28, 2023
CVE-2023-39015
9.8

CVE-2023-39015 is a critical code injection vulnerability in webmagic-extension's PhantomJSDownloader component that allows remote attackers to execut...

Jul 28, 2023
CVE-2023-3519
9.8

CVE-2023-3519 is an unauthenticated remote code execution vulnerability in Citrix ADC and Citrix Gateway appliances. Attackers can exploit this withou...

Jul 19, 2023
CVE-2021-37384
9.8

CVE-2021-37384 is a critical remote code execution vulnerability affecting certain Furukawa ONU (Optical Network Unit) models. Unauthenticated attacke...

Jul 17, 2023
CVE-2023-37466
9.8

CVE-2023-37466 is a critical sandbox escape vulnerability in vm2, a Node.js sandbox library. Attackers can bypass Promise handler sanitization using t...

Jul 14, 2023
CVE-2023-38198
9.8

CVE-2023-38198 is a critical remote code execution vulnerability in acme.sh, an ACME protocol client for obtaining TLS certificates. The vulnerability...

Jul 13, 2023
CVE-2023-37659
9.8

CVE-2023-37659 is a critical Remote Command Execution vulnerability in xalpha v0.11.4 that allows attackers to execute arbitrary commands on affected ...

Jul 11, 2023
CVE-2023-36258
9.8

This vulnerability in LangChain allows attackers to execute arbitrary Python code through malicious inputs containing os.system, exec, or eval functio...

Jul 3, 2023
CVE-2021-31635
9.8

CVE-2021-31635 is a Server-Side Template Injection vulnerability in jFinal framework that allows remote attackers to execute arbitrary code by manipul...

Jun 26, 2023
CVE-2023-35853
9.8

This vulnerability allows an adversary who controls an external source of Lua rules to execute arbitrary Lua code in Suricata. It affects Suricata ins...

Jun 19, 2023
CVE-2023-35813
9.8

This critical vulnerability allows remote attackers to execute arbitrary code on affected Sitecore systems without authentication. It affects Sitecore...

Jun 17, 2023
CVE-2023-3224
9.8

This vulnerability allows remote code execution through improper input validation in Nuxt.js. Attackers can inject malicious code that gets executed o...

Jun 13, 2023
CVE-2023-35034
9.8

This critical vulnerability in Atos Unify OpenScape 4000 Assistant and Manager allows unauthenticated remote attackers to execute arbitrary code on af...

Jun 12, 2023
CVE-2023-29404
9.8

This vulnerability in Go's cgo build system allows malicious Go modules to execute arbitrary code during the build process. Attackers can smuggle dang...

Jun 8, 2023
CVE-2023-29402
9.8

This CVE-2023-29402 is a critical code injection vulnerability in Go's cgo build system. It allows attackers to execute arbitrary code during build ti...

Jun 8, 2023
CVE-2020-36708
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary PHP functions via the epsilon_framework_ajax_action in vulnerable WordPress t...

Jun 7, 2023
CVE-2023-32692
9.8

CVE-2023-32692 is a critical remote code execution vulnerability in CodeIgniter's Validation library. Attackers can execute arbitrary PHP code by expl...

May 30, 2023
CVE-2023-30145
9.8

Camaleon CMS v2.7.0 contains a Server-Side Template Injection vulnerability in the formats parameter that allows attackers to execute arbitrary code o...

May 26, 2023
CVE-2023-25953
9.8

A code injection vulnerability in LINE WORKS Drive Explorer for macOS allows authenticated attackers to execute arbitrary code with full disk access p...

May 23, 2023
CVE-2023-29861
9.8

CVE-2023-29861 is a critical remote code execution vulnerability in FLIR-DVTEL camera devices that allows attackers to execute arbitrary code via craf...

May 15, 2023
CVE-2023-29862
9.8

This vulnerability allows remote attackers to execute arbitrary code on Agasio Camera devices by manipulating the check and authLevel parameters. It a...

May 15, 2023
CVE-2022-47129
9.8

PHPOK v6.3 contains a remote code execution vulnerability (CWE-94: Improper Control of Generation of Code) that allows attackers to execute arbitrary ...

May 11, 2023
CVE-2023-30349
9.8

JFinal CMS v5.1.0 contains a critical remote code execution vulnerability in the ActionEnter function that allows attackers to execute arbitrary code ...

Apr 27, 2023
CVE-2023-30404
9.8

This vulnerability allows remote attackers to execute arbitrary code on Aigital Wireless-N Repeater Mini_Router devices by sending a specially crafted...

Apr 26, 2023
CVE-2020-29007
9.8

This vulnerability allows remote code execution in MediaWiki installations using the Score extension. Any user with article edit permissions (includin...

Apr 15, 2023
CVE-2023-29492
9.8

CVE-2023-29492 is a critical remote code execution vulnerability in Novi Survey software that allows attackers to execute arbitrary commands on affect...

Apr 11, 2023
CVE-2023-27650
9.8

This vulnerability allows remote attackers to execute arbitrary code on devices running vulnerable versions of APUS Group Launcher by exploiting the F...

Apr 10, 2023
CVE-2023-28706
9.8

This CVE allows remote code execution through improper input validation in Apache Airflow Hive Provider. Attackers can inject malicious code that gets...

Apr 7, 2023
CVE-2023-26119
9.8

This vulnerability allows remote code execution via XSLT processing in HtmlUnit when browsing malicious webpages. Attackers can execute arbitrary code...

Apr 3, 2023
CVE-2023-25261
9.8

This vulnerability allows remote code execution in Stimulsoft reporting products by exploiting improper input validation. Attackers can craft maliciou...

Mar 27, 2023
CVE-2023-28333
9.8

CVE-2023-28333 is a Mustache template injection vulnerability in Moodle's pix helper that could allow remote code execution if user input is improperl...

Mar 23, 2023
CVE-2023-24795
9.8

A command execution vulnerability in JHR-N916R router firmware allows attackers to execute arbitrary commands on affected devices, potentially gaining...

Mar 16, 2023
CVE-2023-25344
9.8

This vulnerability in Swig template engines allows attackers to execute arbitrary code by exploiting prototype pollution in Object.prototype. It affec...

Mar 15, 2023
CVE-2023-24776
9.8

Funadmin v3.2.0 contains a remote code execution vulnerability in the Addon.php controller component that allows attackers to execute arbitrary code o...

Mar 6, 2023
CVE-2022-45553
9.8

This vulnerability allows attackers to execute arbitrary commands on Shenzhen Zhibotong Electronics WBT WE1626 routers by connecting to the UART seria...

Mar 3, 2023

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free