CWE-96
CVEs classified under CWE-96, newest first.
2 CVEsRSS
CVE-2026-68489High· 8.7Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
▾ TwilightWebPros · Plesk extension "Ruby"EPSS 0.40%via NVD
CVE-2026-86218Critical· 9.8CISA KEVPoCN-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
▾ Hadaln-able · n-centralEPSS 7.5%via NVD