Vulnerabilities (CVE)

Filtered by CWE-94
Total 6527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-25357 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 9.8 CRITICAL
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
CVE-2018-25320 2026-06-17 N/A 9.8 CRITICAL
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.
CVE-2018-25114 2026-06-17 N/A N/A
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application later includes this file, the injected payload is executed, resulting in full server-side compromise.
CVE-2018-21023 1 Centreon 1 Centreon Web 2026-06-17 6.5 MEDIUM 8.8 HIGH
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
CVE-2018-21005 1 Bbpress Move Topics Project 1 Bbpress Move Topics 2026-06-17 7.5 HIGH 9.8 CRITICAL
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
CVE-2018-20988 1 Google Forms Project 1 Google Forms 2026-06-17 5.0 MEDIUM 7.5 HIGH
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
CVE-2018-20931 1 Cpanel 1 Cpanel 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
CVE-2018-20896 1 Cpanel 1 Cpanel 2026-06-17 3.3 LOW 3.9 LOW
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
CVE-2018-20775 1 Frog Cms Project 1 Frog Cms 2026-06-17 6.5 MEDIUM 7.2 HIGH
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
CVE-2018-20773 1 Frog Cms Project 1 Frog Cms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
CVE-2018-20772 1 Frog Cms Project 1 Frog Cms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
CVE-2018-20768 1 Xerox 58 Workcentre 3655, Workcentre 3655 Firmware, Workcentre 3655i and 55 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
CVE-2018-20717 1 Prestashop 1 Prestashop 2026-06-17 6.5 MEDIUM 8.8 HIGH
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the process and abuse an object chain in order to gain Remote Code Execution. This occurs because protection against serialized objects looks for a 0: followed by an integer, but does not consider 0:+ followed by an integer.
CVE-2018-20605 1 Txjia 1 Imcat 2026-06-17 7.5 HIGH 9.8 CRITICAL
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
CVE-2018-20599 1 Ucms Project 1 Ucms 2026-06-17 6.5 MEDIUM 8.8 HIGH
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
CVE-2018-20325 1 Definitions Project 1 Definitions 2026-06-17 7.5 HIGH 9.8 CRITICAL
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.
CVE-2018-20300 1 Phome 1 Empirecms 2026-06-17 7.5 HIGH 9.8 CRITICAL
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
CVE-2018-20133 1 Ymlref Project 1 Ymlref 2026-06-17 7.5 HIGH 9.8 CRITICAL
ymlref allows code injection.
CVE-2018-20129 1 Dedecms 1 Dedecms 2026-06-17 6.5 MEDIUM 8.8 HIGH
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.
CVE-2018-20027 1 Lisa-lab 1 Pylearn2 2026-06-17 7.5 HIGH 9.8 CRITICAL
The yaml_parse.load method in Pylearn2 allows code injection.