Skip to content
Noroxi

CWE-96 · 27 records

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

CVEs in this class

27 records

  • CVE-2026-86218
    74This week

    pre-authentication remote code execution

    CriticalCVSS 10.0KEVWeaponizedEPSS 13%

    n-able · n-centralSep 5, 2026

  • Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    HighCVSS 8.8No exploitEPSS 26%

    hitachi · vantara pentaho business analytics serverApr 3, 2023

  • A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    CriticalCVSS 9.8No exploitEPSS 6%

    os4ed · opensisSep 1, 2020

  • A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    CriticalCVSS 9.8No exploitEPSS 6%

    os4ed · opensisSep 1, 2020

  • Static Code Injection in microweber/microweber

    CriticalCVSS 9.8No exploitEPSS 2%

    microweber · microweberMar 10, 2022

  • An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

    CriticalCVSS 9.8No exploitEPSS 1%

    mintty project · minttyOct 26, 2023

  • Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028

    CriticalCVSS 9.8No exploitEPSS 0%

    opigno · opigno moduleJan 9, 2025

  • In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.

    CriticalCVSS 9.4No exploitEPSS 1%

    tiny · moxiemanager phpMar 25, 2025

  • XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

    HighCVSS 8.8No exploitEPSS 2%

    xwiki · xwikiDec 12, 2024

  • CVE-2015-2079
    35Monitor

    Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr

    HighCVSS 8.8No exploitEPSS 2%

    webmin · userminApr 28, 2025

  • XWiki allows remote code execution through the extension sheet

    HighCVSS 8.8No exploitEPSS 1%

    xwiki · xwikiDec 12, 2024

  • Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut

    HighCVSS 8.7No exploitEPSS 1%

    webpros · plesk extension "ruby"Sep 14, 2026

  • less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.

    HighCVSS 8.6No exploitEPSS 1%

    greenwoodsoftware · lessApr 13, 2024

  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

    HighCVSS 8.1No exploit

    npm · serialize-javascriptFeb 28, 2026

  • Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031

    HighCVSS 7.5No exploitEPSS 1%

    opigno · tincan question typeJan 9, 2025

  • Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029

    HighCVSS 7.5No exploitEPSS 1%

    opigno · learning pathJan 9, 2025

  • Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex

    HighCVSS 7.2Proof of conceptEPSS 4%

    atlassian · jira service deskSep 1, 2021

  • Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static

    HighCVSS 7.2No exploitEPSS 1%

    dell · solutions enabler virtual applianceJun 27, 2025

  • Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod

    HighCVSS 7.2No exploitEPSS 0%

    red hat · red hat ansible automation platform 2.7Sep 23, 2026

  • Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032

    MediumCVSS 6.8No exploitEPSS 0%

    opigno · opignoJan 9, 2025

  • CVE-2024-0788
    26Monitor

    SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation

    MediumCVSS 6.6No exploitEPSS 0%

    realdefen · superantispywareJan 29, 2024

  • CVE-2022-3960
    25Monitor

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    MediumCVSS 6.3No exploitEPSS 0%

    hitachi · vantara pentaho business analytics serverApr 3, 2023

  • CVE-2025-7825
    25Monitor

    Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation

    MediumCVSS 6.3No exploitEPSS 0%

    wpt00ls · schema plugin for divi, gutenberg & shortcodesOct 3, 2025

  • XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader

    MediumCVSS 4.6No exploitEPSS 16%

    xwiki · xwikiJul 31, 2024

  • Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027

    MediumCVSS 5.5No exploitEPSS 0%

    opigno · group managerJan 9, 2025

All vulnerability classes