Vulnerabilities (CVE)

Filtered by CWE-94
Total 7148 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30537 1 Xwiki 1 Xwiki 2026-06-17 N/A 9.9 CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles properties `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki versions 13.10.11, 14.4.7 and 14.10.
CVE-2023-30349 1 Jflyfox 1 Jfinal Cms 2026-06-17 N/A 9.8 CRITICAL
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
CVE-2023-30179 1 Craftcms 1 Craft Cms 2026-06-17 N/A 7.2 HIGH
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.
CVE-2023-30145 1 Tuzitio 1 Camaleon Cms 2026-06-17 N/A 9.8 CRITICAL
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
CVE-2023-30131 1 Ixpdata 1 Easyinstall 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.
CVE-2023-30130 1 Craftcms 1 Craft Cms 2026-06-17 N/A 8.8 HIGH
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
CVE-2023-2943 1 Open-emr 1 Openemr 2026-06-17 N/A 8.8 HIGH
Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2928 1 Dedecms 1 Dedecms 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.
CVE-2023-2859 1 Teampass 1 Teampass 2026-06-17 N/A 8.8 HIGH
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-2583 1 Jsreport 1 Jsreport 2026-06-17 N/A 10.0 CRITICAL
Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.
CVE-2023-2359 1 Themepunch 1 Slider Revolution 2026-06-17 N/A 8.8 HIGH
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
CVE-2023-2259 1 Alf 1 Alf 2026-06-17 N/A 7.2 HIGH
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVE-2023-2056 1 Dedecms 1 Dedecms 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225941 was assigned to this vulnerability.
CVE-2023-2017 1 Shopware 1 Shopware 2026-06-17 N/A 8.8 HIGH
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.
CVE-2023-29963 1 S-cms 1 S-cms 2026-06-17 N/A 7.2 HIGH
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
CVE-2023-29862 1 Agasio Camera Project 2 Agasio Camera, Agasio Camera Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
CVE-2023-29861 1 Flir 2 Dvtel Camera, Dvtel Camera Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
CVE-2023-29566 2 Dawnsparks-node-tesseract Project, Huedawn-tesseract Project 2 Dawnsparks-node-tesseract, Huedawn-tesseract 2026-06-17 N/A 9.8 CRITICAL
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
CVE-2023-29509 1 Xwiki 1 Xwiki 2026-06-17 N/A 9.9 CRITICAL
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `documentTree` macro parameters in This macro is installed by default in `FlamingoThemesCode.WebHome`. This page is installed by default. The vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10.
CVE-2023-29492 1 3rdmill 1 Novi Survey 2026-06-17 N/A 9.8 CRITICAL
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.