Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-05-16 CVE-2025-4744 Code Injection vulnerability in Fabian Employee Record System 1.0
A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0.
network
low complexity
fabian CWE-94
4.6
2025-05-16 CVE-2025-4745 Code Injection vulnerability in Fabian Employee Record System 1.0
A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0.
network
low complexity
fabian CWE-94
5.4
2025-05-15 CVE-2025-3053 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.07 via the uip_process_form_input() function.
network
low complexity
CWE-94
8.8
2025-05-13 CVE-2025-4428 Code Injection vulnerability in Ivanti Endpoint Manager Mobile
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
network
low complexity
ivanti CWE-94
8.8
2025-05-13 CVE-2025-43010 SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs.
network
low complexity
CWE-94
8.3
2025-05-11 CVE-2025-4551 A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0.
network
low complexity
CWE-94
3.5
2025-05-10 CVE-2025-4495 A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic.
network
low complexity
CWE-94
3.5
2025-05-09 CVE-2025-4470 Code Injection vulnerability in Senior-Walter Online Student Clearance System 1.0
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0.
network
low complexity
senior-walter CWE-94
5.4
2025-05-09 CVE-2025-4461 Code Injection vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-94
5.4
2025-05-09 CVE-2025-4460 Code Injection vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-94
4.8