CWE-96 · 27 kayıt
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Bu sınıftaki CVE’ler
27 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
74Bu hafta | CVE-2026-86218Silahlaştırılmış | pre-authentication remote code executionn-able · n-central · CWE-96 | Kritik10,0 | KEV | %12,9 | 5 Eyl 2026 |
43Planlayın | CVE-2022-43938İstismar yok | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Yüksek8,8 | — | %26,4 | 3 Nis 2023 |
41Planlayın | CVE-2020-6143İstismar yok | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Kritik9,8 | — | %6,2 | 1 Eyl 2020 |
41Planlayın | CVE-2020-6144İstismar yok | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.os4ed · opensis · CWE-96 | Kritik9,8 | — | %6,2 | 1 Eyl 2020 |
40Planlayın | CVE-2022-0895İstismar yok | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Kritik9,8 | — | %1,7 | 10 Mar 2022 |
39İzleyin | CVE-2023-39726İstismar yok | An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.mintty project · mintty · CWE-96 | Kritik9,8 | — | %1,0 | 26 Eki 2023 |
39İzleyin | CVE-2024-13264İstismar yok | Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028opigno · opigno module · CWE-96 | Kritik9,8 | — | %0,5 | 9 Oca 2025 |
37İzleyin | CVE-2025-30091İstismar yok | In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.tiny · moxiemanager php · CWE-96 | Kritik9,4 | — | %0,8 | 25 Mar 2025 |
35İzleyin | CVE-2024-55877İstismar yok | XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListxwiki · xwiki · CWE-96 | Yüksek8,8 | — | %1,6 | 12 Ara 2024 |
35İzleyin | CVE-2015-2079İstismar yok | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thrwebmin · usermin · CWE-96 | Yüksek8,8 | — | %1,5 | 28 Nis 2025 |
35İzleyin | CVE-2024-55662İstismar yok | XWiki allows remote code execution through the extension sheetxwiki · xwiki · CWE-96 | Yüksek8,8 | — | %0,8 | 12 Ara 2024 |
34İzleyin | CVE-2026-68489İstismar yok | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to executwebpros · plesk extension "ruby" · CWE-96 | Yüksek8,7 | — | %0,7 | 14 Eyl 2026 |
34İzleyin | CVE-2024-32487İstismar yok | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.greenwoodsoftware · less · CWE-96 | Yüksek8,6 | — | %0,6 | 13 Nis 2024 |
32İzleyin | GHSA-5c6j-r48x-rmvqİstismar yok | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()npm · serialize-javascript · CWE-96 | Yüksek8,1 | — | — | 28 Şub 2026 |
30İzleyin | CVE-2024-13267İstismar yok | Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031opigno · tincan question type · CWE-96 | Yüksek7,5 | — | %0,6 | 9 Oca 2025 |
30İzleyin | CVE-2024-13265İstismar yok | Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029opigno · learning path · CWE-96 | Yüksek7,5 | — | %0,6 | 9 Oca 2025 |
29İzleyin | CVE-2021-39115Kavram kanıtı | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to exatlassian · jira service desk · CWE-96 | Yüksek7,2 | — | %4,5 | 1 Eyl 2021 |
28İzleyin | CVE-2025-36595İstismar yok | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static dell · solutions enabler virtual appliance · CWE-96 | Yüksek7,2 | — | %0,7 | 27 Haz 2025 |
28İzleyin | CVE-2026-85475İstismar yok | Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote codred hat · red hat ansible automation platform 2.7 · CWE-96 | Yüksek7,2 | — | %0,4 | 6 gün önce |
27İzleyin | CVE-2024-13268İstismar yok | Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032opigno · opigno · CWE-96 | Orta6,8 | — | %0,5 | 9 Oca 2025 |
26İzleyin | CVE-2024-0788İstismar yok | SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulationrealdefen · superantispyware · CWE-96 | Orta6,6 | — | %0,2 | 29 Oca 2024 |
25İzleyin | CVE-2022-3960İstismar yok | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Orta6,3 | — | %0,5 | 3 Nis 2023 |
25İzleyin | CVE-2025-7825İstismar yok | Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiationwpt00ls · schema plugin for divi, gutenberg & shortcodes · CWE-96 | Orta6,3 | — | %0,3 | 3 Eki 2025 |
23İzleyin | CVE-2024-37900İstismar yok | XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploaderxwiki · xwiki · CWE-96 | Orta4,6 | — | %15,8 | 31 Tem 2024 |
22İzleyin | CVE-2024-13263İstismar yok | Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027opigno · group manager · CWE-96 | Orta5,5 | — | %0,3 | 9 Oca 2025 |
- CVE-2026-8621874Bu hafta
pre-authentication remote code execution
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %13n-able · n-central5 Eyl 2026
- CVE-2022-4393843Planlayın
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
YüksekCVSS 8,8İstismar yokEPSS %26hitachi · vantara pentaho business analytics server3 Nis 2023
- CVE-2020-614341Planlayın
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
KritikCVSS 9,8İstismar yokEPSS %6os4ed · opensis1 Eyl 2020
- CVE-2020-614441Planlayın
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.
KritikCVSS 9,8İstismar yokEPSS %6os4ed · opensis1 Eyl 2020
- CVE-2022-089540Planlayın
Static Code Injection in microweber/microweber
KritikCVSS 9,8İstismar yokEPSS %2microweber · microweber10 Mar 2022
- CVE-2023-3972639İzleyin
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
KritikCVSS 9,8İstismar yokEPSS %1mintty project · mintty26 Eki 2023
- CVE-2024-1326439İzleyin
Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
KritikCVSS 9,8İstismar yokEPSS %0opigno · opigno module9 Oca 2025
- CVE-2025-3009137İzleyin
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.
KritikCVSS 9,4İstismar yokEPSS %1tiny · moxiemanager php25 Mar 2025
- CVE-2024-5587735İzleyin
XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
YüksekCVSS 8,8İstismar yokEPSS %2xwiki · xwiki12 Ara 2024
- CVE-2015-207935İzleyin
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr
YüksekCVSS 8,8İstismar yokEPSS %2webmin · usermin28 Nis 2025
- CVE-2024-5566235İzleyin
XWiki allows remote code execution through the extension sheet
YüksekCVSS 8,8İstismar yokEPSS %1xwiki · xwiki12 Ara 2024
- CVE-2026-6848934İzleyin
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut
YüksekCVSS 8,7İstismar yokEPSS %1webpros · plesk extension "ruby"14 Eyl 2026
- CVE-2024-3248734İzleyin
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.
YüksekCVSS 8,6İstismar yokEPSS %1greenwoodsoftware · less13 Nis 2024
- GHSA-5c6j-r48x-rmvq32İzleyin
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
YüksekCVSS 8,1İstismar yoknpm · serialize-javascript28 Şub 2026
- CVE-2024-1326730İzleyin
Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
YüksekCVSS 7,5İstismar yokEPSS %1opigno · tincan question type9 Oca 2025
- CVE-2024-1326530İzleyin
Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
YüksekCVSS 7,5İstismar yokEPSS %1opigno · learning path9 Oca 2025
- CVE-2021-3911529İzleyin
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex
YüksekCVSS 7,2Kavram kanıtıEPSS %4atlassian · jira service desk1 Eyl 2021
- CVE-2025-3659528İzleyin
Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static
YüksekCVSS 7,2İstismar yokEPSS %1dell · solutions enabler virtual appliance27 Haz 2025
- CVE-2026-8547528İzleyin
Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod
YüksekCVSS 7,2İstismar yokEPSS %0red hat · red hat ansible automation platform 2.76 gün önce
- CVE-2024-1326827İzleyin
Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
OrtaCVSS 6,8İstismar yokEPSS %0opigno · opigno9 Oca 2025
- CVE-2024-078826İzleyin
SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation
OrtaCVSS 6,6İstismar yokEPSS %0realdefen · superantispyware29 Oca 2024
- CVE-2022-396025İzleyin
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
OrtaCVSS 6,3İstismar yokEPSS %0hitachi · vantara pentaho business analytics server3 Nis 2023
- CVE-2025-782525İzleyin
Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
OrtaCVSS 6,3İstismar yokEPSS %0wpt00ls · schema plugin for divi, gutenberg & shortcodes3 Eki 2025
- CVE-2024-3790023İzleyin
XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
OrtaCVSS 4,6İstismar yokEPSS %16xwiki · xwiki31 Tem 2024
- CVE-2024-1326322İzleyin
Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
OrtaCVSS 5,5İstismar yokEPSS %0opigno · group manager9 Oca 2025