Перейти к содержимому
Noroxi

CWE-96 · 27 записей

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

CVE этого класса

27 записей

  • CVE-2026-86218
    74На этой неделе

    pre-authentication remote code execution

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 13 %

    n-able · n-central5 сент. 2026 г.

  • CVE-2022-43938
    43В плане

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %

    hitachi · vantara pentaho business analytics server3 апр. 2023 г.

  • CVE-2020-6143
    41В плане

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    os4ed · opensis1 сент. 2020 г.

  • CVE-2020-6144
    41В плане

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    os4ed · opensis1 сент. 2020 г.

  • CVE-2022-0895
    40В плане

    Static Code Injection in microweber/microweber

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    microweber · microweber10 мар. 2022 г.

  • CVE-2023-39726
    39Наблюдать

    An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mintty project · mintty26 окт. 2023 г.

  • CVE-2024-13264
    39Наблюдать

    Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    opigno · opigno module9 янв. 2025 г.

  • CVE-2025-30091
    37Наблюдать

    In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    tiny · moxiemanager php25 мар. 2025 г.

  • CVE-2024-55877
    35Наблюдать

    XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    xwiki · xwiki12 дек. 2024 г.

  • CVE-2015-2079
    35Наблюдать

    Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    webmin · usermin28 апр. 2025 г.

  • CVE-2024-55662
    35Наблюдать

    XWiki allows remote code execution through the extension sheet

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    xwiki · xwiki12 дек. 2024 г.

  • CVE-2026-68489
    34Наблюдать

    Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    webpros · plesk extension "ruby"14 сент. 2026 г.

  • CVE-2024-32487
    34Наблюдать

    less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    greenwoodsoftware · less13 апр. 2024 г.

  • GHSA-5c6j-r48x-rmvq
    32Наблюдать

    Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

    ВысокаяCVSS 8,1Эксплойта нет

    npm · serialize-javascript28 февр. 2026 г.

  • CVE-2024-13267
    30Наблюдать

    Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    opigno · tincan question type9 янв. 2025 г.

  • CVE-2024-13265
    30Наблюдать

    Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    opigno · learning path9 янв. 2025 г.

  • CVE-2021-39115
    29Наблюдать

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex

    ВысокаяCVSS 7,2Proof of conceptEPSS 4 %

    atlassian · jira service desk1 сент. 2021 г.

  • CVE-2025-36595
    28Наблюдать

    Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    dell · solutions enabler virtual appliance27 июн. 2025 г.

  • CVE-2026-85475
    28Наблюдать

    Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    red hat · red hat ansible automation platform 2.76 дней назад

  • CVE-2024-13268
    27Наблюдать

    Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    opigno · opigno9 янв. 2025 г.

  • CVE-2024-0788
    26Наблюдать

    SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation

    СредняяCVSS 6,6Эксплойта нетEPSS 0 %

    realdefen · superantispyware29 янв. 2024 г.

  • CVE-2022-3960
    25Наблюдать

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    hitachi · vantara pentaho business analytics server3 апр. 2023 г.

  • CVE-2025-7825
    25Наблюдать

    Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    wpt00ls · schema plugin for divi, gutenberg & shortcodes3 окт. 2025 г.

  • CVE-2024-37900
    23Наблюдать

    XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader

    СредняяCVSS 4,6Эксплойта нетEPSS 16 %

    xwiki · xwiki31 июл. 2024 г.

  • CVE-2024-13263
    22Наблюдать

    Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    opigno · group manager9 янв. 2025 г.

Все классы уязвимостей