Vulnerabilities (CVE)

Filtered by CWE-94
Total 6547 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0462 2 Redhat, Theforeman 2 Satellite, Foreman 2026-06-17 N/A 8.0 HIGH
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
CVE-2023-0297 1 Pyload 1 Pyload 2026-06-17 N/A 9.8 CRITICAL
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
CVE-2023-0090 1 Proofpoint 1 Enterprise Protection 2026-06-17 N/A 9.8 CRITICAL
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.
CVE-2023-0089 1 Proofpoint 1 Enterprise Protection 2026-06-17 N/A 8.8 HIGH
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.
CVE-2023-0048 1 Daloradius 1 Daloradius 2026-06-17 N/A 8.8 HIGH
Code Injection in GitHub repository lirantal/daloradius prior to master-branch.
CVE-2023-0022 1 Sap 1 Businessobjects Business Intelligence Platform 2026-06-17 N/A 9.9 CRITICAL
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.
CVE-2022-50806 1 4homepages 1 4images 2026-06-17 N/A 7.2 HIGH
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.
CVE-2022-4455 1 Php-calendar 1 Php-calendar 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It is advisable to implement a patch to correct this issue.
CVE-2022-4300 1 Xjd2020 1 Fastcms 2026-06-17 N/A 6.3 MEDIUM
A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214901 was assigned to this vulnerability.
CVE-2022-48175 1 Rukovoditel 1 Rukovoditel 2026-06-17 N/A 9.8 CRITICAL
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
CVE-2022-48116 1 Ayacms Project 1 Ayacms 2026-06-17 N/A 7.2 HIGH
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
CVE-2022-48093 1 Seacms 1 Seacms 2026-06-17 N/A 7.2 HIGH
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
CVE-2022-47896 1 Jetbrains 1 Intellij Idea 2026-06-17 N/A 5.0 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVE-2022-47318 3 Debian, Fedoraproject, Ruby-git Project 3 Debian Linux, Fedora, Ruby-git 2026-06-17 N/A 8.0 HIGH
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
CVE-2022-47129 1 Phpok 1 Phpok 2026-06-17 N/A 9.8 CRITICAL
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2022-46874 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2026-06-17 N/A 8.8 HIGH
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.
CVE-2022-46836 1 Checkmk 1 Checkmk 2026-06-17 N/A 9.1 CRITICAL
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.
CVE-2022-46742 1 Paddlepaddle 1 Paddlepaddle 2026-06-17 N/A 10.0 CRITICAL
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
CVE-2022-46648 2 Debian, Ruby-git Project 2 Debian Linux, Ruby-git 2026-06-17 N/A 8.0 HIGH
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
CVE-2022-46333 1 Proofpoint 1 Enterprise Protection 2026-06-17 N/A 7.2 HIGH
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below.