Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-05-05 CVE-2025-4293 A vulnerability was found in MRCMS 3.1.3 and classified as problematic.
network
low complexity
CWE-94
2.4
2025-05-05 CVE-2025-44071 Code Injection vulnerability in Seacms 13.3
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.
network
low complexity
seacms CWE-94
critical
9.8
2025-05-05 CVE-2025-24977 Code Injection vulnerability in Citeum Opencti 6.4.10/6.4.8/6.4.9
OpenCTI is an open cyber threat intelligence (CTI) platform.
network
low complexity
citeum CWE-94
critical
9.1
2025-05-05 CVE-2025-4257 A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2.
network
low complexity
CWE-94
3.5
2025-05-03 CVE-2024-13738 The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65.
network
low complexity
CWE-94
7.3
2025-05-02 CVE-2025-2421 Code Injection vulnerability in Felisify Sambabox
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.
network
low complexity
felisify CWE-94
critical
9.8
2025-05-02 CVE-2024-13420 Code Injection vulnerability in G5Plus products
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions.
network
low complexity
g5plus CWE-94
4.3
2025-04-29 CVE-2025-4075 A vulnerability was found in VMSMan up to 20250416.
network
low complexity
CWE-94
4.3
2025-04-28 CVE-2023-42404 Code Injection vulnerability in Onevision Workspace 22.1/22.2/23.1
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
network
low complexity
onevision CWE-94
critical
9.8
2025-04-28 CVE-2015-2079 Code Injection vulnerability in Webmin Usermin
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
network
low complexity
webmin CWE-94
8.8