Skip to content
Noroxi

CWE-84 · 19 records

Improper Neutralization of Encoded URI Schemes in a Web Page

CVEs in this class

19 records

  • MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

    HighCVSS 8.6No exploitEPSS 1%

    modelcontextprotocol · inspectorSep 8, 2025

  • A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), D

    HighCVSS 8.3No exploitEPSS 1%

    siemens · desigo pxm30-1 firmwareOct 11, 2022

  • Plex Media Server URL injection

    MediumCVSS 6.9No exploitEPSS 0%

    plex · media serverSep 23, 2026

  • Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction

    MediumCVSS 6.3No exploitEPSS 1%

    red hat · red hat enterprise linux 6Sep 10, 2026

  • CVE-2020-7011
    24Monitor

    Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.

    MediumCVSS 6.1No exploitEPSS 1%

    elastic · elastic app searchJun 3, 2020

  • CVE-2021-3824
    24Monitor

    OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

    MediumCVSS 6.1No exploitEPSS 1%

    openvpn · openvpn access serverSep 23, 2021

  • JavaScript Injection via url encoded values in links in Collabora Office Android

    MediumCVSS 6.1No exploitEPSS 0%

    collabora · onlineAug 29, 2024

  • IBM Engineering Lifecycle Optimization - Publishing cross-site scripting

    MediumCVSS 6.1No exploitEPSS 0%

    ibm · engineering lifecycle optimizationAug 5, 2025

  • An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user in

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informati

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informati

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a c

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted lin

    MediumCVSS 5.5No exploitEPSS 0%

    Feb 27, 2025

  • Stored XSS via javascript URI in Apollo Change Requests comment

    MediumCVSS 5.4No exploitEPSS 0%

    palantir · apollo autopilotSep 27, 2023

  • JupyterLab before 4.5.9 Stored XSS via Extension Manager

    MediumCVSS 5.1No exploitEPSS 0%

    jupyterlab · jupyterlabAug 1, 2026

  • HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme

    LowCVSS 2.5No exploitEPSS 0%

    hcl software · bigfix patch management download plug-insJan 22, 2025

All vulnerability classes