CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,153
Total CVEs
521
Critical
513
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Moodle 7
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,153)

CVE-2023-24114
9.8

Typecho 1.1/17.10.30 contains a remote code execution vulnerability in install.php that allows attackers to execute arbitrary code on vulnerable serve...

Feb 22, 2023
CVE-2023-22855
9.8

CVE-2023-22855 is a critical remote code execution vulnerability in Kardex Mlog MCC warehouse management software. It allows attackers to upload malic...

Feb 15, 2023
CVE-2021-36424
9.8

This critical vulnerability in phpwcms allows remote attackers to execute arbitrary code during the installation process by manipulating the database ...

Feb 3, 2023
CVE-2022-30083
9.8

CVE-2022-30083 is a critical code injection vulnerability in the EllieGrid Android app version 3.4.1 that allows attackers to execute arbitrary code b...

Jul 30, 2022
CVE-2022-35649
9.8

This critical Moodle vulnerability allows remote code execution through improper PostScript parsing in GhostScript. Attackers can exploit it to take c...

Jul 25, 2022
CVE-2022-32417
9.8

PbootCMS v3.1.2 contains a remote code execution vulnerability in the parserIfLabel function that allows attackers to execute arbitrary code on affect...

Jul 14, 2022
CVE-2022-0885
9.8

CVE-2022-0885 is a critical vulnerability in the Member Hero WordPress plugin that allows unauthenticated attackers to execute arbitrary PHP functions...

Jun 13, 2022
CVE-2021-41749
9.8

CVE-2021-41749 is a critical Server-Side Template Injection vulnerability in the SEOmatic plugin for Craft CMS that allows unauthenticated attackers t...

Jun 12, 2022
CVE-2022-21831
9.8

This is a critical code injection vulnerability in Ruby on Rails Active Storage that allows attackers to execute arbitrary code by manipulating image_...

May 26, 2022
CVE-2022-29078
9.8

CVE-2022-29078 is a critical server-side template injection vulnerability in the EJS package for Node.js that allows remote code execution. Attackers ...

Apr 25, 2022
CVE-2022-22954
9.8

This vulnerability allows remote attackers to execute arbitrary code on VMware Workspace ONE Access and Identity Manager systems through server-side t...

Apr 11, 2022
CVE-2022-22963
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Spring Cloud Function. Attackers can cr...

Apr 1, 2022
CVE-2021-39383
9.8

DWSurvey v3.2.0 contains a remote command execution vulnerability in the SysPropertyAction.java component that allows attackers to execute arbitrary c...

Mar 20, 2022
CVE-2020-25197
9.8

This vulnerability allows authenticated remote attackers to inject and execute arbitrary code on GE Reason RT430, RT431, and RT434 GNSS clock devices....

Mar 18, 2022
CVE-2020-15591
9.8

CVE-2020-15591 is an eval injection vulnerability in F*EX's fexsrv component that allows unauthenticated remote code execution. Attackers can execute ...

Mar 17, 2022
CVE-2022-25498
9.8

CVE-2022-25498 is a critical remote code execution vulnerability in CuppaCMS v1.0 that allows attackers to execute arbitrary code on affected systems ...

Mar 15, 2022
CVE-2021-25003
9.8

This vulnerability in the WPCargo Track & Trace WordPress plugin allows unauthenticated attackers to write arbitrary PHP files anywhere on the web ser...

Mar 14, 2022
CVE-2021-44618
9.8

This CVE describes a Server-side Template Injection (SSTI) vulnerability in Nystudio107 Seomatic plugin for Craft CMS. Attackers can exploit this by m...

Mar 11, 2022
CVE-2022-0845
9.8

CVE-2022-0845 is a critical code injection vulnerability in PyTorch Lightning that allows attackers to execute arbitrary code by exploiting improper i...

Mar 5, 2022
CVE-2022-24442
9.8

This CVE describes a Server-Side Template Injection (SSTI) vulnerability in JetBrains YouTrack that allows attackers to execute arbitrary code on the ...

Feb 25, 2022
CVE-2021-44978
9.8

This CVE describes a server-side template injection (SSTI) vulnerability in iCMS that allows authenticated users to add and render custom templates, l...

Feb 4, 2022
CVE-2021-45029
9.8

CVE-2021-45029 is a critical vulnerability in Apache ShenYu that allows attackers to inject malicious Groovy or SpEL code, leading to remote code exec...

Jan 25, 2022
CVE-2021-39979
9.8

CVE-2021-39979 is a critical code injection vulnerability in HHEE systems that allows attackers to execute arbitrary code. This affects HarmonyOS devi...

Jan 3, 2022
CVE-2020-20601
9.8

This vulnerability in ThinkCMF X2.2.2 and earlier allows attackers to execute arbitrary code via crafted packets, leading to remote code execution. It...

Dec 22, 2021
CVE-2021-44529
9.8

This is a critical remote code execution vulnerability in Ivanti Cloud Services Appliance (CSA) that allows unauthenticated attackers to execute arbit...

Dec 8, 2021
CVE-2021-41653
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WR840N EU v5 routers by sending a specially crafted payload to the ...

Nov 13, 2021
CVE-2021-33816
9.8

CVE-2021-33816 allows remote attackers to execute arbitrary PHP code on Dolibarr installations through the website builder module. The vulnerability e...

Nov 10, 2021
CVE-2021-43466
9.8

CVE-2021-43466 is a critical remote code execution vulnerability in thymeleaf-spring5 version 3.0.12 where template injection in specific scenarios al...

Nov 9, 2021
CVE-2020-23037
9.8

This vulnerability allows attackers to inject and execute arbitrary web scripts or HTML code through a crafted POST request targeting the filename par...

Oct 22, 2021
CVE-2021-22961
9.8

This vulnerability allows attackers to execute arbitrary code on systems running GlassWire firewall software by exploiting a code injection flaw durin...

Oct 18, 2021
CVE-2021-40499
9.8

CVE-2021-40499 is a critical code injection vulnerability in SAP Cloud Print Manager and SAPSprint components of SAP NetWeaver Application Server for ...

Oct 12, 2021
CVE-2021-40889
9.8

CMSUno 1.7.2 contains a PHP code execution vulnerability that allows attackers to inject malicious PHP code into the password.php file. This enables r...

Oct 11, 2021
CVE-2021-42139
9.8

CVE-2021-42139 is a critical code injection vulnerability in Deno Standard Modules that allows remote code execution when processing untrusted YAML fi...

Oct 11, 2021
CVE-2020-21651
9.8

CVE-2020-21651 is a critical remote code execution vulnerability in Myucms v2.2.1 that allows attackers to execute arbitrary code on affected systems ...

Oct 6, 2021
CVE-2021-40323
9.8

CVE-2021-40323 is a critical vulnerability in Cobbler that allows attackers to poison log files through XMLRPC methods, leading to remote code executi...

Oct 4, 2021
CVE-2021-40373
9.8

CVE-2021-40373 is a critical remote code execution vulnerability in playSMS that allows attackers to execute arbitrary PHP code on affected systems. T...

Sep 10, 2021
CVE-2021-29772
9.8

CVE-2021-29772 is a critical code injection vulnerability in IBM API Connect that allows attackers to execute arbitrary code by exploiting unsanitized...

Aug 26, 2021
CVE-2021-40084
9.8

CVE-2021-40084 is a critical vulnerability in opensysusers (versions through 0.6) that allows remote code execution via shell injection in the GECOS f...

Aug 25, 2021
CVE-2020-22937
9.8

This vulnerability allows remote attackers to execute arbitrary PHP code on EmpireCMS 7.5 installations by writing malicious code to the install.php f...

Aug 17, 2021
CVE-2021-38196
9.8

This vulnerability in the better-macro Rust crate allows remote attackers to execute arbitrary code through malicious proc-macros. The crate intention...

Aug 8, 2021
CVE-2020-18172
9.8

CVE-2020-18172 is a critical code injection vulnerability in Trezor Bridge 2.0.27 that allows attackers to execute arbitrary code with elevated privil...

Jul 26, 2021
CVE-2021-23389
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of total.js framework. Attackers can explo...

Jul 12, 2021
CVE-2021-35514
9.8

CVE-2021-35514 is a critical code injection vulnerability in Narou.rb that allows attackers to execute arbitrary Ruby code by manipulating novel title...

Jun 28, 2021
CVE-2020-21784
9.8

CVE-2020-21784 is a critical code injection vulnerability in phpwcms 1.9.13 that allows attackers to execute arbitrary code via the /phpwcms/setup/set...

Jun 24, 2021
CVE-2021-30461
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on VoIPmonitor systems by injecting malicious code into confi...

May 29, 2021
CVE-2021-23344
9.8

This vulnerability in total.js framework allows remote attackers to execute arbitrary code on affected systems by exploiting improper input validation...

Mar 4, 2021
CVE-2021-25283
9.8

This vulnerability allows server-side template injection (SSTI) in SaltStack Salt's Jinja renderer, enabling attackers to execute arbitrary code on Sa...

Feb 27, 2021
CVE-2021-26120
9.8

CVE-2021-26120 is a critical code injection vulnerability in Smarty template engine that allows attackers to execute arbitrary PHP code via specially ...

Feb 22, 2021
CVE-2020-35339
9.8

CVE-2020-35339 is a critical remote code execution vulnerability in 74cms version 5.0.1 that allows attackers to execute arbitrary code on affected se...

Feb 17, 2021
CVE-2021-25770
9.8

This vulnerability is a server-side template injection (SSTI) in JetBrains YouTrack, allowing attackers to inject malicious templates that can execute...

Feb 3, 2021

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,153 CVEs classified as CWE-94, with 521 rated critical and 513 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free