Skip to content
Noroxi

CWE-790 · 14 records

Improper Filtering of Special Elements

CVEs in this class

14 records

  • A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    facebook · tac plusOct 6, 2023

  • Duplicate advisory: Sequelize vulnerable to Improper Filtering of Special Elements

    CriticalCVSS 10.0No exploit

    npm · @sequelize/coreFeb 16, 2023

  • Sequalize - Default support for “raw attributes” when using parentheses

    CriticalCVSS 9.8No exploitEPSS 1%

    sequelizejs · sequelizeFeb 16, 2023

  • Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports

    HighCVSS 8.8No exploitEPSS 2%

    etherpad · etherpadDec 9, 2021

  • An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(0715

    HighCVSS 8.8No exploitEPSS 1%

    Apr 23, 2024

  • Multiple issues in ctl(4) CAM Target Layer

    HighCVSS 8.8No exploitEPSS 0%

    freebsd · freebsdSep 5, 2024

  • Potential wildcard CNAME RPZ policy bypass

    HighCVSS 7.5No exploitEPSS 0%

    isc · bind 9Jul 22, 2026

  • CVE-2026-2328
    30Monitor

    Backend Access Due to Insufficient Input Validation

    HighCVSS 7.5No exploitEPSS 0%

    wago · device sphereMar 30, 2026

  • Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability

    HighCVSS 7.2No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareMar 25, 2026

  • Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability.

    MediumCVSS 6.5No exploitEPSS 0%

    dell · recoverpoint for virtual machinesDec 13, 2024

  • CVE-2025-0431
    23Monitor

    Enterprise Protection Backslash URL Rewrite Bypass

    MediumCVSS 5.8No exploitEPSS 0%

    proofpoint · enterprise protectionMar 19, 2025

  • CVE-2024-6540
    21Monitor

    Information exlosure in external interface

    MediumCVSS 5.3No exploitEPSS 0%

    otrs · otrsJul 15, 2024

  • Stored XSS in System Configuration

    MediumCVSS 4.9No exploitEPSS 0%

    otrs ag · otrsAug 26, 2024

  • Stored XSS in process management

    MediumCVSS 4.9No exploitEPSS 0%

    otrs ag · otrsAug 26, 2024

All vulnerability classes