Skip to main content

CWE archive

CWE-96 CVEs

Programmatic archive

23 CVEs tagged with CWE-9610 Critical, 6 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2025-57707

Published Feb 11, 2026

An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a…

CVSS 1.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7825

Published Oct 3, 2025

The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of un…

CVSS 6.3 · Medium

CVE-2015-2079

Published Apr 28, 2025

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30091

Published Mar 25, 2025

In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrar…

CVSS 9.4 · Critical

CVE-2024-13268

Published Jan 9, 2025

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno:…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13267

Published Jan 9, 2025

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13265

Published Jan 9, 2025

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue af…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13264

Published Jan 9, 2025

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects O…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-13263

Published Jan 9, 2025

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue af…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55877

Published Dec 12, 2024

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote c…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55662

Published Dec 12, 2024

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is i…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43400

Published Aug 19, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37900

Published Jul 31, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScri…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0788

Published Jan 29, 2024

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the sa…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39726

Published Oct 26, 2023

An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-6144

Published Sep 1, 2020

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in install/Step5.php allows for inje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-6143

Published Sep 1, 2020

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for inje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1