Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-94

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,687
Assigned CVEs
13th
Commonality Rank
7.6
Avg CVSS
1.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-94 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 1996
30 years ago
Most Recent CVE
Jul 26, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

6,687 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34197HIGH
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the
Apr 7, 20268.899YESYES
CVE-2026-33017CRITICAL
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building
Mar 20, 20269.899YESYES
CVE-2025-32432CRITICAL
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15,
Apr 25, 202510.099YESYES
CVE-2025-3248CRITICAL
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e
Apr 7, 20259.899YESYES
CVE-2025-24893CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to
Feb 20, 20259.899YESYES
CVE-2024-23692CRITICAL
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe
May 31, 20249.899YESYES
CVE-2023-3519CRITICAL
Unauthenticated remote code execution
Jul 19, 20239.899YESYES
CVE-2022-22963CRITICAL
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
CVE-2022-22947CRITICAL
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse
Mar 3, 202210.099YESYES
CVE-2021-44529CRITICAL
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
Dec 8, 20219.899YESYES
View all 6,687 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
8%
19%
5.0-5.9
15%
16%
6.0-6.9
21%
26%
7.0-7.9
14%
11%
8.0-8.9
31%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
76 CVEs
1.1% of CVEs· 92nd percentile
Metasploit
190 CVEs
2.8% of CVEs· 95th percentile
Nuclei
153 CVEs
2.3% of CVEs· 90th percentile
ExploitDB
1,132 CVEs
16.9% of CVEs· 99th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products