CWE-76 · 14 records
Improper Neutralization of Equivalent Special Elements
CVEs in this class
14 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2024-34359No exploit | llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadataabetlen · llama-cpp-python · CWE-76 | Critical9.6 | — | 26.0% | May 14, 2024 |
42Plan | CVE-2024-1883No exploit | Reflected XSS in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Medium6.1 | — | 61.5% | Mar 14, 2024 |
39Monitor | CVE-2024-2952No exploit | Server-Side Template Injection in BerriAI/litellmlitellm · litellm · CWE-76 | Critical9.8 | — | 1.3% | Apr 10, 2024 |
37Monitor | CVE-2023-0493Proof of concept | Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserverbtcpayserver · btcpay server · CWE-76 | High8.8 | — | 7.9% | Jan 26, 2023 |
34Monitor | CVE-2026-66362No exploit | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configf5 · nginx gateway fabric · CWE-76 | High8.6 | — | 0.6% | Sep 2, 2026 |
34Monitor | CVE-2026-54722No exploit | dssrf: there a critical security bug with remove_at_symbol_in_stringhackingrepo · dssrf-js · CWE-76 | High8.7 | — | 0.6% | Jul 30, 2026 |
34Monitor | CVE-2026-11311No exploit | NGINX Gateway Fabric vulnerabilityf5 · nginx gateway fabric · CWE-76 | High8.6 | — | 0.6% | Jun 17, 2026 |
34Monitor | CVE-2026-55723No exploit | NGINX Ingress Controller vulnerabilityf5 · nginx ingress controller · CWE-76 | High8.7 | — | 0.5% | Jul 15, 2026 |
34Monitor | CVE-2026-77180No exploit | NGINX Ingress Controller vulnerabilityf5 · nginx ingress controller · CWE-76 | High8.7 | — | 0.5% | Sep 2, 2026 |
33Monitor | CVE-2024-4897No exploit | Remote Code Execution in parisneo/lollms-webuilollms · lollms web ui · CWE-76 | High8.4 | — | 0.4% | Jul 2, 2024 |
28Monitor | CVE-2024-1882No exploit | Server-side resource injection in PaperCut NG/MFpapercut · papercut mf · CWE-76 | High7.2 | — | 1.4% | Mar 14, 2024 |
26Monitor | CVE-2024-21600No exploit | Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge conditionjuniper · junos · CWE-76 | Medium6.5 | — | 0.3% | Jan 11, 2024 |
21Monitor | CVE-2023-1149No exploit | Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserverbtcpayserver · btcpay server · CWE-76 | Medium5.4 | — | 0.5% | Mar 2, 2023 |
12Monitor | CVE-2024-1221No exploit | Improper access controls on APIs on Linux and macOS in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Low3.1 | — | 0.5% | Mar 13, 2024 |
- CVE-2024-3435946Plan
llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
CriticalCVSS 9.6No exploitEPSS 26%abetlen · llama-cpp-pythonMay 14, 2024
- CVE-2024-188342Plan
Reflected XSS in PaperCut NG/MF
MediumCVSS 6.1No exploitEPSS 61%papercut · papercut mfMar 14, 2024
- CVE-2024-295239Monitor
Server-Side Template Injection in BerriAI/litellm
CriticalCVSS 9.8No exploitEPSS 1%litellm · litellmApr 10, 2024
- CVE-2023-049337Monitor
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
HighCVSS 8.8Proof of conceptEPSS 8%btcpayserver · btcpay serverJan 26, 2023
- CVE-2026-6636234Monitor
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX config
HighCVSS 8.6No exploitEPSS 1%f5 · nginx gateway fabricSep 2, 2026
- CVE-2026-5472234Monitor
dssrf: there a critical security bug with remove_at_symbol_in_string
HighCVSS 8.7No exploitEPSS 1%hackingrepo · dssrf-jsJul 30, 2026
- CVE-2026-1131134Monitor
NGINX Gateway Fabric vulnerability
HighCVSS 8.6No exploitEPSS 1%f5 · nginx gateway fabricJun 17, 2026
- CVE-2026-5572334Monitor
NGINX Ingress Controller vulnerability
HighCVSS 8.7No exploitEPSS 1%f5 · nginx ingress controllerJul 15, 2026
- CVE-2026-7718034Monitor
NGINX Ingress Controller vulnerability
HighCVSS 8.7No exploitEPSS 0%f5 · nginx ingress controllerSep 2, 2026
- CVE-2024-489733Monitor
Remote Code Execution in parisneo/lollms-webui
HighCVSS 8.4No exploitEPSS 0%lollms · lollms web uiJul 2, 2024
- CVE-2024-188228Monitor
Server-side resource injection in PaperCut NG/MF
HighCVSS 7.2No exploitEPSS 1%papercut · papercut mfMar 14, 2024
- CVE-2024-2160026Monitor
Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition
MediumCVSS 6.5No exploitEPSS 0%juniper · junosJan 11, 2024
- CVE-2023-114921Monitor
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
MediumCVSS 5.4No exploitEPSS 1%btcpayserver · btcpay serverMar 2, 2023
- CVE-2024-122112Monitor
Improper access controls on APIs on Linux and macOS in PaperCut NG/MF
LowCVSS 3.1No exploitEPSS 1%papercut · papercut mfMar 13, 2024