Vulnerabilities (CVE)

Filtered by CWE-94
Total 6557 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27622 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 7.2 HIGH
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
CVE-2024-27476 1 Leantime 1 Leantime 2026-06-17 N/A 4.7 MEDIUM
Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
CVE-2024-27191 2026-06-17 N/A 8.5 HIGH
Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion.This issue affects Slivery Extender: from n/a through <= 1.0.2.
CVE-2024-26483 1 Getkirby 1 Kirby 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.
CVE-2024-26362 3 Enpass, Linux, Microsoft 3 Password Manager, Linux Kernel, Windows 2026-06-17 N/A 8.8 HIGH
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
CVE-2024-25918 1 Instawp 1 Instawp Connect 2026-06-17 N/A 9.9 CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
CVE-2024-25713 2 Fedoraproject, Ibireme 2 Fedora, Yyjson 2026-06-17 N/A 8.6 HIGH
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
CVE-2024-25706 1 Esri 1 Portal For Arcgis 2026-06-17 N/A 6.1 MEDIUM
There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.
CVE-2024-25624 1 Dfir-iris 1 Iris 2026-06-17 N/A 6.8 MEDIUM
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation of the vulnerability can lead to an arbitrary Remote Code Execution. An authenticated administrator has to upload a crafted report template containing the payload. Upon generation of a report based on the weaponized report, any user can trigger the vulnerability. The vulnerability is patched in IRIS v2.4.6. No workaround is available. It is recommended to update as soon as possible. Until patching, review the report templates and keep the administrative privileges that include the upload of report templates limited to dedicated users.
CVE-2024-25600 2026-06-17 N/A 10.0 CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
CVE-2024-25502 1 Flusity 1 Flusity 2026-06-17 N/A 9.8 CRITICAL
Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.
CVE-2024-25415 1 Phoenixcart 1 Ce Phoenix Cart 2026-06-17 N/A 7.2 HIGH
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
CVE-2024-25376 1 Thesycon 1 Tusbaudio 2026-06-17 N/A 7.8 HIGH
An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.
CVE-2024-25359 1 Zuoxingdong 1 Lagom 2026-06-17 N/A 6.6 MEDIUM
An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.
CVE-2024-25350 1 Phpgurukul 1 Zoo Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
CVE-2024-25301 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
CVE-2024-25298 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
CVE-2024-25293 1 Mjml 1 Mjml App 2026-06-17 N/A 9.3 CRITICAL
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
CVE-2024-25291 1 Deskfiler 1 Deskfiler 2026-06-17 N/A 9.8 CRITICAL
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
CVE-2024-25249 1 He3app 1 He3 App 2026-06-17 N/A 9.8 CRITICAL
An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.