İçeriğe atla
Noroxi

CWE-96 · 27 kayıt

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

Bu sınıftaki CVE’ler

27 kayıt

  • CVE-2026-86218
    74Bu hafta

    pre-authentication remote code execution

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %13

    n-able · n-central5 Eyl 2026

  • CVE-2022-43938
    43Planlayın

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    YüksekCVSS 8,8İstismar yokEPSS %26

    hitachi · vantara pentaho business analytics server3 Nis 2023

  • CVE-2020-6143
    41Planlayın

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    KritikCVSS 9,8İstismar yokEPSS %6

    os4ed · opensis1 Eyl 2020

  • CVE-2020-6144
    41Planlayın

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4.

    KritikCVSS 9,8İstismar yokEPSS %6

    os4ed · opensis1 Eyl 2020

  • CVE-2022-0895
    40Planlayın

    Static Code Injection in microweber/microweber

    KritikCVSS 9,8İstismar yokEPSS %2

    microweber · microweber10 Mar 2022

  • CVE-2023-39726
    39İzleyin

    An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

    KritikCVSS 9,8İstismar yokEPSS %1

    mintty project · mintty26 Eki 2023

  • CVE-2024-13264
    39İzleyin

    Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028

    KritikCVSS 9,8İstismar yokEPSS %0

    opigno · opigno module9 Oca 2025

  • CVE-2025-30091
    37İzleyin

    In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command.

    KritikCVSS 9,4İstismar yokEPSS %1

    tiny · moxiemanager php25 Mar 2025

  • CVE-2024-55877
    35İzleyin

    XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

    YüksekCVSS 8,8İstismar yokEPSS %2

    xwiki · xwiki12 Ara 2024

  • CVE-2015-2079
    35İzleyin

    Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not thr

    YüksekCVSS 8,8İstismar yokEPSS %2

    webmin · usermin28 Nis 2025

  • CVE-2024-55662
    35İzleyin

    XWiki allows remote code execution through the extension sheet

    YüksekCVSS 8,8İstismar yokEPSS %1

    xwiki · xwiki12 Ara 2024

  • CVE-2026-68489
    34İzleyin

    Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut

    YüksekCVSS 8,7İstismar yokEPSS %1

    webpros · plesk extension "ruby"14 Eyl 2026

  • CVE-2024-32487
    34İzleyin

    less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c.

    YüksekCVSS 8,6İstismar yokEPSS %1

    greenwoodsoftware · less13 Nis 2024

  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

    YüksekCVSS 8,1İstismar yok

    npm · serialize-javascript28 Şub 2026

  • CVE-2024-13267
    30İzleyin

    Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031

    YüksekCVSS 7,5İstismar yokEPSS %1

    opigno · tincan question type9 Oca 2025

  • CVE-2024-13265
    30İzleyin

    Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029

    YüksekCVSS 7,5İstismar yokEPSS %1

    opigno · learning path9 Oca 2025

  • CVE-2021-39115
    29İzleyin

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to ex

    YüksekCVSS 7,2Kavram kanıtıEPSS %4

    atlassian · jira service desk1 Eyl 2021

  • CVE-2025-36595
    28İzleyin

    Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static

    YüksekCVSS 7,2İstismar yokEPSS %1

    dell · solutions enabler virtual appliance27 Haz 2025

  • CVE-2026-85475
    28İzleyin

    Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote cod

    YüksekCVSS 7,2İstismar yokEPSS %0

    red hat · red hat ansible automation platform 2.76 gün önce

  • CVE-2024-13268
    27İzleyin

    Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032

    OrtaCVSS 6,8İstismar yokEPSS %0

    opigno · opigno9 Oca 2025

  • CVE-2024-0788
    26İzleyin

    SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation

    OrtaCVSS 6,6İstismar yokEPSS %0

    realdefen · superantispyware29 Oca 2024

  • CVE-2022-3960
    25İzleyin

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

    OrtaCVSS 6,3İstismar yokEPSS %0

    hitachi · vantara pentaho business analytics server3 Nis 2023

  • CVE-2025-7825
    25İzleyin

    Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation

    OrtaCVSS 6,3İstismar yokEPSS %0

    wpt00ls · schema plugin for divi, gutenberg & shortcodes3 Eki 2025

  • CVE-2024-37900
    23İzleyin

    XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader

    OrtaCVSS 4,6İstismar yokEPSS %16

    xwiki · xwiki31 Tem 2024

  • CVE-2024-13263
    22İzleyin

    Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027

    OrtaCVSS 5,5İstismar yokEPSS %0

    opigno · group manager9 Oca 2025

Tüm zafiyet sınıfları