CVE-2025-31340

CRITICAL Year: 2025

Vulnerability Description

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

CVSS:9.9(Critical)

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CWE-982023
CVSS:9.8(Critical)

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file ...

CWE-982014
CVSS:9.8(Critical)

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow...

CWE-982022
CVSS:9.8(Critical)

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CWE-982022
CVSS:9.8(Critical)

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unau...

CWE-982024
CVSS:9.8(Critical)

The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This makes it possible for ...

CWE-982024