CWE-96 · 27 records
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CVEs in this class
27 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
74This week | CVE-2026-86218Weaponized | pre-authentication remote code executionn-able · n-central · CWE-96 | Critical10.0 | KEV | 12.9% | Sep 5, 2026 |
43Plan | CVE-2022-43938No exploit | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | High8.8 | — | 26.4% | Apr 3, 2023 |
41Plan | CVE-2020-6143No exploit | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Critical9.8 | — | 6.2% | Sep 1, 2020 |
41Plan | CVE-2020-6144No exploit | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Critical9.8 | — | 6.2% | Sep 1, 2020 |
40Plan | CVE-2022-0895No exploit | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Critical9.8 | — | 1.7% | Mar 10, 2022 |
39Monitor | CVE-2023-39726No exploit | An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.mintty project · mintty · CWE-96 | Critical9.8 | — | 1.0% | Oct 26, 2023 |
39Monitor | CVE-2024-13264No exploit | Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028opigno · opigno module · CWE-96 | Critical9.8 | — | 0.5% | Jan 9, 2025 |
37Monitor | CVE-2025-30091No exploit | In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.tiny · moxiemanager php · CWE-96 | Critical9.4 | — | 0.8% | Mar 25, 2025 |
35Monitor | CVE-2024-55877No exploit | XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListxwiki · xwiki · CWE-96 | High8.8 | — | 1.6% | Dec 12, 2024 |
35Monitor | CVE-2015-2079No exploit | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thrwebmin · usermin · CWE-96 | High8.8 | — | 1.5% | Apr 28, 2025 |
35Monitor | CVE-2024-55662No exploit | XWiki allows remote code execution through the extension sheetxwiki · xwiki · CWE-96 | High8.8 | — | 0.8% | Dec 12, 2024 |
34Monitor | CVE-2026-68489No exploit | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to executwebpros · plesk extension "ruby" · CWE-96 | High8.7 | — | 0.7% | Sep 14, 2026 |
34Monitor | CVE-2024-32487No exploit | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.greenwoodsoftware · less · CWE-96 | High8.6 | — | 0.6% | Apr 13, 2024 |
32Monitor | GHSA-5c6j-r48x-rmvqNo exploit | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()npm · serialize-javascript · CWE-96 | High8.1 | — | — | Feb 28, 2026 |
30Monitor | CVE-2024-13267No exploit | Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031opigno · tincan question type · CWE-96 | High7.5 | — | 0.6% | Jan 9, 2025 |
30Monitor | CVE-2024-13265No exploit | Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029opigno · learning path · CWE-96 | High7.5 | — | 0.6% | Jan 9, 2025 |
29Monitor | CVE-2021-39115Proof of concept | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to exatlassian · jira service desk · CWE-96 | High7.2 | — | 4.5% | Sep 1, 2021 |
28Monitor | CVE-2025-36595No exploit | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static dell · solutions enabler virtual appliance · CWE-96 | High7.2 | — | 0.7% | Jun 27, 2025 |
28Monitor | CVE-2026-85475No exploit | Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote codred hat · red hat ansible automation platform 2.7 · CWE-96 | High7.2 | — | 0.4% | Sep 23, 2026 |
27Monitor | CVE-2024-13268No exploit | Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032opigno · opigno · CWE-96 | Medium6.8 | — | 0.5% | Jan 9, 2025 |
26Monitor | CVE-2024-0788No exploit | SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulationrealdefen · superantispyware · CWE-96 | Medium6.6 | — | 0.2% | Jan 29, 2024 |
25Monitor | CVE-2022-3960No exploit | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Medium6.3 | — | 0.5% | Apr 3, 2023 |
25Monitor | CVE-2025-7825No exploit | Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiationwpt00ls · schema plugin for divi, gutenberg & shortcodes · CWE-96 | Medium6.3 | — | 0.3% | Oct 3, 2025 |
23Monitor | CVE-2024-37900No exploit | XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploaderxwiki · xwiki · CWE-96 | Medium4.6 | — | 15.8% | Jul 31, 2024 |
22Monitor | CVE-2024-13263No exploit | Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027opigno · group manager · CWE-96 | Medium5.5 | — | 0.3% | Jan 9, 2025 |
- CVE-2026-8621874This week
pre-authentication remote code execution
CriticalCVSS 10.0KEVWeaponizedEPSS 13%n-able · n-centralSep 5, 2026
- CVE-2022-4393843Plan
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
HighCVSS 8.8No exploitEPSS 26%hitachi · vantara pentaho business analytics serverApr 3, 2023
- CVE-2020-614341Plan
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
CriticalCVSS 9.8No exploitEPSS 6%os4ed · opensisSep 1, 2020
- CVE-2020-614441Plan
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
CriticalCVSS 9.8No exploitEPSS 6%os4ed · opensisSep 1, 2020
- CVE-2022-089540Plan
Static Code Injection in microweber/microweber
CriticalCVSS 9.8No exploitEPSS 2%microweber · microweberMar 10, 2022
- CVE-2023-3972639Monitor
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
CriticalCVSS 9.8No exploitEPSS 1%mintty project · minttyOct 26, 2023
- CVE-2024-1326439Monitor
Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
CriticalCVSS 9.8No exploitEPSS 0%opigno · opigno moduleJan 9, 2025
- CVE-2025-3009137Monitor
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.
CriticalCVSS 9.4No exploitEPSS 1%tiny · moxiemanager phpMar 25, 2025
- CVE-2024-5587735Monitor
XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
HighCVSS 8.8No exploitEPSS 2%xwiki · xwikiDec 12, 2024
- CVE-2015-207935Monitor
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr
HighCVSS 8.8No exploitEPSS 2%webmin · userminApr 28, 2025
- CVE-2024-5566235Monitor
XWiki allows remote code execution through the extension sheet
HighCVSS 8.8No exploitEPSS 1%xwiki · xwikiDec 12, 2024
- CVE-2026-6848934Monitor
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut
HighCVSS 8.7No exploitEPSS 1%webpros · plesk extension "ruby"Sep 14, 2026
- CVE-2024-3248734Monitor
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.
HighCVSS 8.6No exploitEPSS 1%greenwoodsoftware · lessApr 13, 2024
- GHSA-5c6j-r48x-rmvq32Monitor
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
HighCVSS 8.1No exploitnpm · serialize-javascriptFeb 28, 2026
- CVE-2024-1326730Monitor
Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
HighCVSS 7.5No exploitEPSS 1%opigno · tincan question typeJan 9, 2025
- CVE-2024-1326530Monitor
Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
HighCVSS 7.5No exploitEPSS 1%opigno · learning pathJan 9, 2025
- CVE-2021-3911529Monitor
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex
HighCVSS 7.2Proof of conceptEPSS 4%atlassian · jira service deskSep 1, 2021
- CVE-2025-3659528Monitor
Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static
HighCVSS 7.2No exploitEPSS 1%dell · solutions enabler virtual applianceJun 27, 2025
- CVE-2026-8547528Monitor
Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod
HighCVSS 7.2No exploitEPSS 0%red hat · red hat ansible automation platform 2.7Sep 23, 2026
- CVE-2024-1326827Monitor
Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
MediumCVSS 6.8No exploitEPSS 0%opigno · opignoJan 9, 2025
- CVE-2024-078826Monitor
SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation
MediumCVSS 6.6No exploitEPSS 0%realdefen · superantispywareJan 29, 2024
- CVE-2022-396025Monitor
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
MediumCVSS 6.3No exploitEPSS 0%hitachi · vantara pentaho business analytics serverApr 3, 2023
- CVE-2025-782525Monitor
Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
MediumCVSS 6.3No exploitEPSS 0%wpt00ls · schema plugin for divi, gutenberg & shortcodesOct 3, 2025
- CVE-2024-3790023Monitor
XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
MediumCVSS 4.6No exploitEPSS 16%xwiki · xwikiJul 31, 2024
- CVE-2024-1326322Monitor
Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
MediumCVSS 5.5No exploitEPSS 0%opigno · group managerJan 9, 2025