CWE-96 · 27 записей
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CVE этого класса
27 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
74На этой неделе | CVE-2026-86218Готовый эксплойт | pre-authentication remote code executionn-able · n-central · CWE-96 | Критическая10,0 | KEV | 12,9 % | 5 сент. 2026 г. |
43В плане | CVE-2022-43938Эксплойта нет | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Высокая8,8 | — | 26,4 % | 3 апр. 2023 г. |
41В плане | CVE-2020-6143Эксплойта нет | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Критическая9,8 | — | 6,2 % | 1 сент. 2020 г. |
41В плане | CVE-2020-6144Эксплойта нет | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Критическая9,8 | — | 6,2 % | 1 сент. 2020 г. |
40В плане | CVE-2022-0895Эксплойта нет | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Критическая9,8 | — | 1,7 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2023-39726Эксплойта нет | An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.mintty project · mintty · CWE-96 | Критическая9,8 | — | 1,0 % | 26 окт. 2023 г. |
39Наблюдать | CVE-2024-13264Эксплойта нет | Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028opigno · opigno module · CWE-96 | Критическая9,8 | — | 0,5 % | 9 янв. 2025 г. |
37Наблюдать | CVE-2025-30091Эксплойта нет | In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.tiny · moxiemanager php · CWE-96 | Критическая9,4 | — | 0,8 % | 25 мар. 2025 г. |
35Наблюдать | CVE-2024-55877Эксплойта нет | XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListxwiki · xwiki · CWE-96 | Высокая8,8 | — | 1,6 % | 12 дек. 2024 г. |
35Наблюдать | CVE-2015-2079Эксплойта нет | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thrwebmin · usermin · CWE-96 | Высокая8,8 | — | 1,5 % | 28 апр. 2025 г. |
35Наблюдать | CVE-2024-55662Эксплойта нет | XWiki allows remote code execution through the extension sheetxwiki · xwiki · CWE-96 | Высокая8,8 | — | 0,8 % | 12 дек. 2024 г. |
34Наблюдать | CVE-2026-68489Эксплойта нет | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to executwebpros · plesk extension "ruby" · CWE-96 | Высокая8,7 | — | 0,7 % | 14 сент. 2026 г. |
34Наблюдать | CVE-2024-32487Эксплойта нет | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.greenwoodsoftware · less · CWE-96 | Высокая8,6 | — | 0,6 % | 13 апр. 2024 г. |
32Наблюдать | GHSA-5c6j-r48x-rmvqЭксплойта нет | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()npm · serialize-javascript · CWE-96 | Высокая8,1 | — | — | 28 февр. 2026 г. |
30Наблюдать | CVE-2024-13267Эксплойта нет | Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031opigno · tincan question type · CWE-96 | Высокая7,5 | — | 0,6 % | 9 янв. 2025 г. |
30Наблюдать | CVE-2024-13265Эксплойта нет | Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029opigno · learning path · CWE-96 | Высокая7,5 | — | 0,6 % | 9 янв. 2025 г. |
29Наблюдать | CVE-2021-39115Proof of concept | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to exatlassian · jira service desk · CWE-96 | Высокая7,2 | — | 4,5 % | 1 сент. 2021 г. |
28Наблюдать | CVE-2025-36595Эксплойта нет | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static dell · solutions enabler virtual appliance · CWE-96 | Высокая7,2 | — | 0,7 % | 27 июн. 2025 г. |
28Наблюдать | CVE-2026-85475Эксплойта нет | Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote codred hat · red hat ansible automation platform 2.7 · CWE-96 | Высокая7,2 | — | 0,4 % | 6 дней назад |
27Наблюдать | CVE-2024-13268Эксплойта нет | Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032opigno · opigno · CWE-96 | Средняя6,8 | — | 0,5 % | 9 янв. 2025 г. |
26Наблюдать | CVE-2024-0788Эксплойта нет | SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulationrealdefen · superantispyware · CWE-96 | Средняя6,6 | — | 0,2 % | 29 янв. 2024 г. |
25Наблюдать | CVE-2022-3960Эксплойта нет | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Средняя6,3 | — | 0,5 % | 3 апр. 2023 г. |
25Наблюдать | CVE-2025-7825Эксплойта нет | Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiationwpt00ls · schema plugin for divi, gutenberg & shortcodes · CWE-96 | Средняя6,3 | — | 0,3 % | 3 окт. 2025 г. |
23Наблюдать | CVE-2024-37900Эксплойта нет | XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploaderxwiki · xwiki · CWE-96 | Средняя4,6 | — | 15,8 % | 31 июл. 2024 г. |
22Наблюдать | CVE-2024-13263Эксплойта нет | Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027opigno · group manager · CWE-96 | Средняя5,5 | — | 0,3 % | 9 янв. 2025 г. |
- CVE-2026-8621874На этой неделе
pre-authentication remote code execution
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 13 %n-able · n-central5 сент. 2026 г.
- CVE-2022-4393843В плане
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2020-614341В плане
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %os4ed · opensis1 сент. 2020 г.
- CVE-2020-614441В плане
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %os4ed · opensis1 сент. 2020 г.
- CVE-2022-089540В плане
Static Code Injection in microweber/microweber
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microweber · microweber10 мар. 2022 г.
- CVE-2023-3972639Наблюдать
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mintty project · mintty26 окт. 2023 г.
- CVE-2024-1326439Наблюдать
Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %opigno · opigno module9 янв. 2025 г.
- CVE-2025-3009137Наблюдать
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %tiny · moxiemanager php25 мар. 2025 г.
- CVE-2024-5587735Наблюдать
XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xwiki · xwiki12 дек. 2024 г.
- CVE-2015-207935Наблюдать
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %webmin · usermin28 апр. 2025 г.
- CVE-2024-5566235Наблюдать
XWiki allows remote code execution through the extension sheet
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %xwiki · xwiki12 дек. 2024 г.
- CVE-2026-6848934Наблюдать
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %webpros · plesk extension "ruby"14 сент. 2026 г.
- CVE-2024-3248734Наблюдать
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %greenwoodsoftware · less13 апр. 2024 г.
- GHSA-5c6j-r48x-rmvq32Наблюдать
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
ВысокаяCVSS 8,1Эксплойта нетnpm · serialize-javascript28 февр. 2026 г.
- CVE-2024-1326730Наблюдать
Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opigno · tincan question type9 янв. 2025 г.
- CVE-2024-1326530Наблюдать
Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opigno · learning path9 янв. 2025 г.
- CVE-2021-3911529Наблюдать
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex
ВысокаяCVSS 7,2Proof of conceptEPSS 4 %atlassian · jira service desk1 сент. 2021 г.
- CVE-2025-3659528Наблюдать
Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %dell · solutions enabler virtual appliance27 июн. 2025 г.
- CVE-2026-8547528Наблюдать
Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %red hat · red hat ansible automation platform 2.76 дней назад
- CVE-2024-1326827Наблюдать
Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
СредняяCVSS 6,8Эксплойта нетEPSS 0 %opigno · opigno9 янв. 2025 г.
- CVE-2024-078826Наблюдать
SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation
СредняяCVSS 6,6Эксплойта нетEPSS 0 %realdefen · superantispyware29 янв. 2024 г.
- CVE-2022-396025Наблюдать
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
СредняяCVSS 6,3Эксплойта нетEPSS 0 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2025-782525Наблюдать
Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
СредняяCVSS 6,3Эксплойта нетEPSS 0 %wpt00ls · schema plugin for divi, gutenberg & shortcodes3 окт. 2025 г.
- CVE-2024-3790023Наблюдать
XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
СредняяCVSS 4,6Эксплойта нетEPSS 16 %xwiki · xwiki31 июл. 2024 г.
- CVE-2024-1326322Наблюдать
Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
СредняяCVSS 5,5Эксплойта нетEPSS 0 %opigno · group manager9 янв. 2025 г.