The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Volume of CVEs assigned to CWE-94 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6,687 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34197HIGH Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the | Apr 7, 2026 | 8.8 | 99 | YES | YES |
CVE-2026-33017CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building | Mar 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-32432CRITICAL Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, | Apr 25, 2025 | 10.0 | 99 | YES | YES |
CVE-2025-3248CRITICAL Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e | Apr 7, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-24893CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to | Feb 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-23692CRITICAL Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe | May 31, 2024 | 9.8 | 99 | YES | YES |
CVE-2023-3519CRITICAL Unauthenticated remote code execution | Jul 19, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-22963CRITICAL In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r | Apr 1, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-22947CRITICAL In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse | Mar 3, 2022 | 10.0 | 99 | YES | YES |
CVE-2021-44529CRITICAL A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | Dec 8, 2021 | 9.8 | 99 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.