Vulnerabilities (CVE)

Filtered by CWE-94
Total 6581 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29902 2026-06-17 N/A 10.0 CRITICAL
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
CVE-2025-29807 1 Microsoft 1 Dataverse 2026-06-17 N/A 8.7 HIGH
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
CVE-2025-29806 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 6.5 MEDIUM
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2025-29662 1 Landchat 1 Landchat 2026-06-17 N/A 9.8 CRITICAL
A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.
CVE-2025-29661 1 Litepublisher 1 Litepubl Cms 2026-06-17 N/A 7.2 HIGH
Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
CVE-2025-29631 2026-06-17 N/A 9.8 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit.
CVE-2025-29629 2026-06-17 N/A 9.1 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
CVE-2025-29401 1 Emlog 1 Emlog 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29306 1 Foxcms 1 Foxcms 2026-06-17 N/A 9.8 CRITICAL
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
CVE-2025-29281 1 Perfree 1 Perfreeblog 2026-06-17 N/A 8.8 HIGH
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
CVE-2025-29064 1 Totolink 2 X18, X18 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
CVE-2025-29058 1 Qimou Cms Project 1 Qimou Cms 2026-06-17 N/A 9.8 CRITICAL
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-29039 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 7.2 HIGH
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
CVE-2025-28993 2026-06-17 N/A 8.6 HIGH
Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue affects Content No Cache: from n/a through <= 0.1.4.
CVE-2025-28893 2026-06-17 N/A 9.9 CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1.
CVE-2025-28386 1 Openc3 1 Cosmos 2026-06-17 N/A 9.8 CRITICAL
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.
CVE-2025-28203 1 Govicture 2 Rx1800, Rx1800 Firmware 2026-06-17 N/A 8.8 HIGH
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
CVE-2025-28146 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
CVE-2025-27998 2026-06-17 N/A 8.4 HIGH
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.
CVE-2025-27678 1 Printerlogic 2 Vasion Print, Virtual Appliance 2026-06-17 N/A 9.8 CRITICAL
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.