Skip to content
Noroxi

CWE-76 · 14 records

Improper Neutralization of Equivalent Special Elements

CVEs in this class

14 records

  • llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

    CriticalCVSS 9.6No exploitEPSS 26%

    abetlen · llama-cpp-pythonMay 14, 2024

  • Reflected XSS in PaperCut NG/MF

    MediumCVSS 6.1No exploitEPSS 61%

    papercut · papercut mfMar 14, 2024

  • CVE-2024-2952
    39Monitor

    Server-Side Template Injection in BerriAI/litellm

    CriticalCVSS 9.8No exploitEPSS 1%

    litellm · litellmApr 10, 2024

  • CVE-2023-0493
    37Monitor

    Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver

    HighCVSS 8.8Proof of conceptEPSS 8%

    btcpayserver · btcpay serverJan 26, 2023

  • Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX config

    HighCVSS 8.6No exploitEPSS 1%

    f5 · nginx gateway fabricSep 2, 2026

  • dssrf: there a critical security bug with remove_at_symbol_in_string

    HighCVSS 8.7No exploitEPSS 1%

    hackingrepo · dssrf-jsJul 30, 2026

  • NGINX Gateway Fabric vulnerability

    HighCVSS 8.6No exploitEPSS 1%

    f5 · nginx gateway fabricJun 17, 2026

  • NGINX Ingress Controller vulnerability

    HighCVSS 8.7No exploitEPSS 1%

    f5 · nginx ingress controllerJul 15, 2026

  • NGINX Ingress Controller vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    f5 · nginx ingress controllerSep 2, 2026

  • CVE-2024-4897
    33Monitor

    Remote Code Execution in parisneo/lollms-webui

    HighCVSS 8.4No exploitEPSS 0%

    lollms · lollms web uiJul 2, 2024

  • CVE-2024-1882
    28Monitor

    Server-side resource injection in PaperCut NG/MF

    HighCVSS 7.2No exploitEPSS 1%

    papercut · papercut mfMar 14, 2024

  • Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition

    MediumCVSS 6.5No exploitEPSS 0%

    juniper · junosJan 11, 2024

  • CVE-2023-1149
    21Monitor

    Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver

    MediumCVSS 5.4No exploitEPSS 1%

    btcpayserver · btcpay serverMar 2, 2023

  • CVE-2024-1221
    12Monitor

    Improper access controls on APIs on Linux and macOS in PaperCut NG/MF

    LowCVSS 3.1No exploitEPSS 1%

    papercut · papercut mfMar 13, 2024

All vulnerability classes