Vulnerabilities (CVE)

Filtered by CWE-94
Total 7125 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-70364 2026-07-05 N/A 8.8 HIGH
An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4.
CVE-2026-31018 1 Dolibarr 1 Dolibarr Erp\/crm 2026-07-05 N/A 8.8 HIGH
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
CVE-2025-66848 1 Jdcloud 12 Ax1800, Ax1800 Firmware, Ax3000 and 9 more 2026-07-05 N/A 9.8 CRITICAL
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
CVE-2025-65854 1 Mineadmin 1 Mineadmin 2026-07-05 N/A 9.8 CRITICAL
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.
CVE-2025-61260 2026-07-05 N/A 9.8 CRITICAL
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.
CVE-2025-57567 2026-07-05 N/A 9.1 CRITICAL
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution of system commands.
CVE-2025-56588 1 Dolibarr 1 Dolibarr Erp\/crm 2026-07-05 N/A 8.8 HIGH
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
CVE-2025-56399 2026-07-05 N/A 8.8 HIGH
alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file is still saved on the server. The attacker can then use the rename API to change the file extension to `.php`, and upon accessing it via a public URL, the server executes the embedded code.
CVE-2025-53867 2026-07-05 N/A 9.8 CRITICAL
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
CVE-2025-45947 1 Phpgurukul 1 Online Banquet Booking System 2026-07-05 N/A 9.8 CRITICAL
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component
CVE-2025-25789 1 Foxcms 1 Foxcms 2026-07-05 N/A 9.8 CRITICAL
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
CVE-2025-22906 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
CVE-2025-22905 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
CVE-2024-54999 1 Monicahq 1 Monica 2026-07-05 N/A 6.5 MEDIUM
MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.
CVE-2024-54997 1 Monicahq 1 Monica 2026-07-05 N/A 5.4 MEDIUM
MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.
CVE-2024-54996 1 Monicahq 1 Monica 2026-07-05 N/A 8.8 HIGH
MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.
CVE-2024-54724 2026-07-05 N/A 9.8 CRITICAL
PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.
CVE-2024-51367 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.
CVE-2024-50808 1 Seacms 1 Seacms 2026-07-05 N/A 8.8 HIGH
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
CVE-2024-45933 2026-07-05 N/A 6.6 MEDIUM
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.