Vulnerabilities (CVE)

Filtered by CWE-94
Total 6568 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48840 1 Abb 38 Aspect-ent-12, Aspect-ent-12 Firmware, Aspect-ent-2 and 35 more 2026-06-17 N/A 10.0 CRITICAL
Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVE-2024-48839 1 Abb 38 Aspect-ent-12, Aspect-ent-12 Firmware, Aspect-ent-2 and 35 more 2026-06-17 N/A 10.0 CRITICAL
Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVE-2024-48829 1 Dell 1 Smartfabric Os10 2026-06-17 N/A 6.7 MEDIUM
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2024-48818 2026-06-17 N/A 9.8 CRITICAL
An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
CVE-2024-48744 1 Phpgurukul 1 Teachers Record Management System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via "searchinput" POST request parameter.
CVE-2024-48700 1 Kliqqi 1 Kliqqi Cms 2026-06-17 N/A 7.2 HIGH
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
CVE-2024-48694 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.
CVE-2024-48655 1 Totaljs 1 Total.js 2026-06-17 N/A 8.8 HIGH
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
CVE-2024-48581 1 Mayurik 1 Best Courier Management System 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
CVE-2024-48579 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
CVE-2024-48514 2026-06-17 N/A 9.8 CRITICAL
php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.
CVE-2024-48453 2026-06-17 N/A 9.8 CRITICAL
An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function
CVE-2024-48359 1 Qualitor 1 Qualitor 2026-06-17 N/A 9.8 CRITICAL
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
CVE-2024-48279 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 7.6 HIGH
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.
CVE-2024-48236 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 6.5 MEDIUM
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
CVE-2024-48235 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 6.5 MEDIUM
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
CVE-2024-48204 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-48168 1 Dlink 2 Dcs-960l, Dcs-960l Firmware 2026-06-17 N/A 9.8 CRITICAL
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
CVE-2024-48138 2026-06-17 N/A 9.8 CRITICAL
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.
CVE-2024-48070 1 Weaver 1 E-cology 2026-06-17 N/A 9.8 CRITICAL
An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges