CWE-790 · 14 records
Improper Filtering of Special Elements
CVEs in this class
14 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-45239Proof of concept | A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker facebook · tac plus · CWE-790 | Critical9.8 | — | 1.9% | Oct 6, 2023 |
40Plan | GHSA-8mwq-mj73-qv68No exploit | Duplicate advisory: Sequelize vulnerable to Improper Filtering of Special Elementsnpm · @sequelize/core · CWE-790 | Critical10.0 | — | — | Feb 16, 2023 |
39Monitor | CVE-2023-22578No exploit | Sequalize - Default support for “raw attributes” when using parenthesessequelizejs · sequelize · CWE-790 | Critical9.8 | — | 0.8% | Feb 16, 2023 |
36Monitor | CVE-2021-43802No exploit | Admin privilege escalation and arbitrary code execution via malicious *.etherpad importsetherpad · etherpad · CWE-790 | High8.8 | — | 2.0% | Dec 9, 2021 |
35Monitor | CVE-2024-31616No exploit | An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(0715CWE-790 | High8.8 | — | 0.8% | Apr 23, 2024 |
35Monitor | CVE-2024-42416No exploit | Multiple issues in ctl(4) CAM Target Layerfreebsd · freebsd · CWE-790 | High8.8 | — | 0.4% | Sep 5, 2024 |
30Monitor | CVE-2026-11331No exploit | Potential wildcard CNAME RPZ policy bypassisc · bind 9 · CWE-790 | High7.5 | — | 0.4% | Jul 22, 2026 |
30Monitor | CVE-2026-2328No exploit | Backend Access Due to Insufficient Input Validationwago · device sphere · CWE-790 | High7.5 | — | 0.3% | Mar 30, 2026 |
28Monitor | CVE-2025-27260No exploit | Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerabilityericsson · indoor connect 8855 firmware · CWE-790 | High7.2 | — | 0.2% | Mar 25, 2026 |
26Monitor | CVE-2024-47984No exploit | Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability.dell · recoverpoint for virtual machines · CWE-790 | Medium6.5 | — | 0.5% | Dec 13, 2024 |
23Monitor | CVE-2025-0431No exploit | Enterprise Protection Backslash URL Rewrite Bypassproofpoint · enterprise protection · CWE-790 | Medium5.8 | — | 0.4% | Mar 19, 2025 |
21Monitor | CVE-2024-6540No exploit | Information exlosure in external interfaceotrs · otrs · CWE-790 | Medium5.3 | — | 0.4% | Jul 15, 2024 |
19Monitor | CVE-2024-43442No exploit | Stored XSS in System Configurationotrs ag · otrs · CWE-790 | Medium4.9 | — | 0.4% | Aug 26, 2024 |
19Monitor | CVE-2024-43443No exploit | Stored XSS in process managementotrs ag · otrs · CWE-790 | Medium4.9 | — | 0.4% | Aug 26, 2024 |
- CVE-2023-4523940Plan
A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker
CriticalCVSS 9.8Proof of conceptEPSS 2%facebook · tac plusOct 6, 2023
- GHSA-8mwq-mj73-qv6840Plan
Duplicate advisory: Sequelize vulnerable to Improper Filtering of Special Elements
CriticalCVSS 10.0No exploitnpm · @sequelize/coreFeb 16, 2023
- CVE-2023-2257839Monitor
Sequalize - Default support for “raw attributes” when using parentheses
CriticalCVSS 9.8No exploitEPSS 1%sequelizejs · sequelizeFeb 16, 2023
- CVE-2021-4380236Monitor
Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
HighCVSS 8.8No exploitEPSS 2%etherpad · etherpadDec 9, 2021
- CVE-2024-3161635Monitor
An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(0715
HighCVSS 8.8No exploitEPSS 1%Apr 23, 2024
- CVE-2024-4241635Monitor
Multiple issues in ctl(4) CAM Target Layer
HighCVSS 8.8No exploitEPSS 0%freebsd · freebsdSep 5, 2024
- CVE-2026-1133130Monitor
Potential wildcard CNAME RPZ policy bypass
HighCVSS 7.5No exploitEPSS 0%isc · bind 9Jul 22, 2026
- CVE-2026-232830Monitor
Backend Access Due to Insufficient Input Validation
HighCVSS 7.5No exploitEPSS 0%wago · device sphereMar 30, 2026
- CVE-2025-2726028Monitor
Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability
HighCVSS 7.2No exploitEPSS 0%ericsson · indoor connect 8855 firmwareMar 25, 2026
- CVE-2024-4798426Monitor
Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability.
MediumCVSS 6.5No exploitEPSS 0%dell · recoverpoint for virtual machinesDec 13, 2024
- CVE-2025-043123Monitor
Enterprise Protection Backslash URL Rewrite Bypass
MediumCVSS 5.8No exploitEPSS 0%proofpoint · enterprise protectionMar 19, 2025
- CVE-2024-654021Monitor
Information exlosure in external interface
MediumCVSS 5.3No exploitEPSS 0%otrs · otrsJul 15, 2024
- CVE-2024-4344219Monitor
Stored XSS in System Configuration
MediumCVSS 4.9No exploitEPSS 0%otrs ag · otrsAug 26, 2024
- CVE-2024-4344319Monitor
Stored XSS in process management
MediumCVSS 4.9No exploitEPSS 0%otrs ag · otrsAug 26, 2024