Total
7125 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-70364 | 2026-07-05 | N/A | 8.8 HIGH | ||
| An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4. | |||||
| CVE-2026-31018 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation. | |||||
| CVE-2025-66848 | 1 Jdcloud | 12 Ax1800, Ax1800 Firmware, Ax3000 and 9 more | 2026-07-05 | N/A | 9.8 CRITICAL |
| JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability. | |||||
| CVE-2025-65854 | 1 Mineadmin | 1 Mineadmin | 2026-07-05 | N/A | 9.8 CRITICAL |
| Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. | |||||
| CVE-2025-61260 | 2026-07-05 | N/A | 9.8 CRITICAL | ||
| A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately. | |||||
| CVE-2025-57567 | 2026-07-05 | N/A | 9.1 CRITICAL | ||
| A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution of system commands. | |||||
| CVE-2025-56588 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter. | |||||
| CVE-2025-56399 | 2026-07-05 | N/A | 8.8 HIGH | ||
| alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file is still saved on the server. The attacker can then use the rename API to change the file extension to `.php`, and upon accessing it via a public URL, the server executes the embedded code. | |||||
| CVE-2025-53867 | 2026-07-05 | N/A | 9.8 CRITICAL | ||
| Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL. | |||||
| CVE-2025-45947 | 1 Phpgurukul | 1 Online Banquet Booking System | 2026-07-05 | N/A | 9.8 CRITICAL |
| An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component | |||||
| CVE-2025-25789 | 1 Foxcms | 1 Foxcms | 2026-07-05 | N/A | 9.8 CRITICAL |
| FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php. | |||||
| CVE-2025-22906 | 1 Edimax | 2 Re11s, Re11s Firmware | 2026-07-05 | N/A | 9.8 CRITICAL |
| RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN. | |||||
| CVE-2025-22905 | 1 Edimax | 2 Re11s, Re11s Firmware | 2026-07-05 | N/A | 9.8 CRITICAL |
| RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. | |||||
| CVE-2024-54999 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 6.5 MEDIUM |
| MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module. | |||||
| CVE-2024-54997 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 5.4 MEDIUM |
| MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit. | |||||
| CVE-2024-54996 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 8.8 HIGH |
| MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create. | |||||
| CVE-2024-54724 | 2026-07-05 | N/A | 9.8 CRITICAL | ||
| PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion. | |||||
| CVE-2024-51367 | 2026-07-05 | N/A | 9.8 CRITICAL | ||
| An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file. | |||||
| CVE-2024-50808 | 1 Seacms | 1 Seacms | 2026-07-05 | N/A | 8.8 HIGH |
| SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php. | |||||
| CVE-2024-45933 | 2026-07-05 | N/A | 6.6 MEDIUM | ||
| OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint. | |||||
