CWE-76 · 14 записей
Improper Neutralization of Equivalent Special Elements
CVE этого класса
14 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2024-34359Эксплойта нет | llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadataabetlen · llama-cpp-python · CWE-76 | Критическая9,6 | — | 26,0 % | 14 мая 2024 г. |
42В плане | CVE-2024-1883Эксплойта нет | Reflected XSS in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Средняя6,1 | — | 61,5 % | 14 мар. 2024 г. |
39Наблюдать | CVE-2024-2952Эксплойта нет | Server-Side Template Injection in BerriAI/litellmlitellm · litellm · CWE-76 | Критическая9,8 | — | 1,3 % | 10 апр. 2024 г. |
37Наблюдать | CVE-2023-0493Proof of concept | Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserverbtcpayserver · btcpay server · CWE-76 | Высокая8,8 | — | 7,9 % | 26 янв. 2023 г. |
34Наблюдать | CVE-2026-66362Эксплойта нет | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configf5 · nginx gateway fabric · CWE-76 | Высокая8,6 | — | 0,6 % | 2 сент. 2026 г. |
34Наблюдать | CVE-2026-54722Эксплойта нет | dssrf: there a critical security bug with remove_at_symbol_in_stringhackingrepo · dssrf-js · CWE-76 | Высокая8,7 | — | 0,6 % | 30 июл. 2026 г. |
34Наблюдать | CVE-2026-11311Эксплойта нет | NGINX Gateway Fabric vulnerabilityf5 · nginx gateway fabric · CWE-76 | Высокая8,6 | — | 0,6 % | 17 июн. 2026 г. |
34Наблюдать | CVE-2026-55723Эксплойта нет | NGINX Ingress Controller vulnerabilityf5 · nginx ingress controller · CWE-76 | Высокая8,7 | — | 0,5 % | 15 июл. 2026 г. |
34Наблюдать | CVE-2026-77180Эксплойта нет | NGINX Ingress Controller vulnerabilityf5 · nginx ingress controller · CWE-76 | Высокая8,7 | — | 0,5 % | 2 сент. 2026 г. |
33Наблюдать | CVE-2024-4897Эксплойта нет | Remote Code Execution in parisneo/lollms-webuilollms · lollms web ui · CWE-76 | Высокая8,4 | — | 0,4 % | 2 июл. 2024 г. |
28Наблюдать | CVE-2024-1882Эксплойта нет | Server-side resource injection in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Высокая7,2 | — | 1,4 % | 14 мар. 2024 г. |
26Наблюдать | CVE-2024-21600Эксплойта нет | Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge conditionjuniper · junos · CWE-76 | Средняя6,5 | — | 0,3 % | 11 янв. 2024 г. |
21Наблюдать | CVE-2023-1149Эксплойта нет | Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserverbtcpayserver · btcpay server · CWE-76 | Средняя5,4 | — | 0,5 % | 2 мар. 2023 г. |
12Наблюдать | CVE-2024-1221Эксплойта нет | Improper access controls on APIs on Linux and macOS in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Низкая3,1 | — | 0,5 % | 13 мар. 2024 г. |
- CVE-2024-3435946В плане
llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
КритическаяCVSS 9,6Эксплойта нетEPSS 26 %abetlen · llama-cpp-python14 мая 2024 г.
- CVE-2024-188342В плане
Reflected XSS in PaperCut NG/MF
СредняяCVSS 6,1Эксплойта нетEPSS 61 %papercut · papercut mf14 мар. 2024 г.
- CVE-2024-295239Наблюдать
Server-Side Template Injection in BerriAI/litellm
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %litellm · litellm10 апр. 2024 г.
- CVE-2023-049337Наблюдать
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %btcpayserver · btcpay server26 янв. 2023 г.
- CVE-2026-6636234Наблюдать
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX config
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %f5 · nginx gateway fabric2 сент. 2026 г.
- CVE-2026-5472234Наблюдать
dssrf: there a critical security bug with remove_at_symbol_in_string
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %hackingrepo · dssrf-js30 июл. 2026 г.
- CVE-2026-1131134Наблюдать
NGINX Gateway Fabric vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %f5 · nginx gateway fabric17 июн. 2026 г.
- CVE-2026-5572334Наблюдать
NGINX Ingress Controller vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %f5 · nginx ingress controller15 июл. 2026 г.
- CVE-2026-7718034Наблюдать
NGINX Ingress Controller vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · nginx ingress controller2 сент. 2026 г.
- CVE-2024-489733Наблюдать
Remote Code Execution in parisneo/lollms-webui
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %lollms · lollms web ui2 июл. 2024 г.
- CVE-2024-188228Наблюдать
Server-side resource injection in PaperCut NG/MF
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %papercut · papercut mf14 мар. 2024 г.
- CVE-2024-2160026Наблюдать
Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition
СредняяCVSS 6,5Эксплойта нетEPSS 0 %juniper · junos11 янв. 2024 г.
- CVE-2023-114921Наблюдать
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
СредняяCVSS 5,4Эксплойта нетEPSS 1 %btcpayserver · btcpay server2 мар. 2023 г.
- CVE-2024-122112Наблюдать
Improper access controls on APIs on Linux and macOS in PaperCut NG/MF
НизкаяCVSS 3,1Эксплойта нетEPSS 1 %papercut · papercut mf13 мар. 2024 г.