CWE-84 · 19 records
Improper Neutralization of Encoded URI Schemes in a Web Page
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2025-58444No exploit | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Servermodelcontextprotocol · inspector · CWE-84 | High8.6 | — | 0.7% | Sep 8, 2025 |
33Monitor | CVE-2022-40181No exploit | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Dsiemens · desigo pxm30-1 firmware · CWE-84 | High8.3 | — | 0.9% | Oct 11, 2022 |
27Monitor | CVE-2026-96654No exploit | Plex Media Server URL injectionplex · media server · CWE-84 | Medium6.9 | — | 0.2% | Sep 23, 2026 |
25Monitor | CVE-2026-88859No exploit | Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restrictionred hat · red hat enterprise linux 6 · CWE-84 | Medium6.3 | — | 0.5% | Sep 10, 2026 |
24Monitor | CVE-2020-7011No exploit | Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.elastic · elastic app search · CWE-84 | Medium6.1 | — | 1.0% | Jun 3, 2020 |
24Monitor | CVE-2021-3824No exploit | OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.openvpn · openvpn access server · CWE-84 | Medium6.1 | — | 0.7% | Sep 23, 2021 |
24Monitor | CVE-2024-45045No exploit | JavaScript Injection via url encoded values in links in Collabora Office Androidcollabora · online · CWE-84 | Medium6.1 | — | 0.3% | Aug 29, 2024 |
24Monitor | CVE-2024-52890No exploit | IBM Engineering Lifecycle Optimization - Publishing cross-site scriptingibm · engineering lifecycle optimization · CWE-84 | Medium6.1 | — | 0.2% | Aug 5, 2025 |
22Monitor | CVE-2025-25326No exploit | An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user inCWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25323No exploit | An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informatiCWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25329No exploit | An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informatiCWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25324No exploit | An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a cCWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25325No exploit | An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via CWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25330No exploit | An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.CWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25331No exploit | An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.CWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
22Monitor | CVE-2025-25334No exploit | An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted linCWE-84 | Medium5.5 | — | 0.2% | Feb 27, 2025 |
21Monitor | CVE-2023-30959No exploit | Stored XSS via javascript URI in Apollo Change Requests commentpalantir · apollo autopilot · CWE-84 | Medium5.4 | — | 0.4% | Sep 27, 2023 |
20Monitor | CVE-2026-67338No exploit | JupyterLab before 4.5.9 Stored XSS via Extension Managerjupyterlab · jupyterlab · CWE-84 | Medium5.1 | — | 0.3% | Aug 1, 2026 |
10Monitor | CVE-2024-42184No exploit | HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI schemehcl software · bigfix patch management download plug-ins · CWE-84 | Low2.5 | — | 0.1% | Jan 22, 2025 |
- CVE-2025-5844434Monitor
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
HighCVSS 8.6No exploitEPSS 1%modelcontextprotocol · inspectorSep 8, 2025
- CVE-2022-4018133Monitor
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), D
HighCVSS 8.3No exploitEPSS 1%siemens · desigo pxm30-1 firmwareOct 11, 2022
- CVE-2026-9665427Monitor
Plex Media Server URL injection
MediumCVSS 6.9No exploitEPSS 0%plex · media serverSep 23, 2026
- CVE-2026-8885925Monitor
Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction
MediumCVSS 6.3No exploitEPSS 1%red hat · red hat enterprise linux 6Sep 10, 2026
- CVE-2020-701124Monitor
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.
MediumCVSS 6.1No exploitEPSS 1%elastic · elastic app searchJun 3, 2020
- CVE-2021-382424Monitor
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
MediumCVSS 6.1No exploitEPSS 1%openvpn · openvpn access serverSep 23, 2021
- CVE-2024-4504524Monitor
JavaScript Injection via url encoded values in links in Collabora Office Android
MediumCVSS 6.1No exploitEPSS 0%collabora · onlineAug 29, 2024
- CVE-2024-5289024Monitor
IBM Engineering Lifecycle Optimization - Publishing cross-site scripting
MediumCVSS 6.1No exploitEPSS 0%ibm · engineering lifecycle optimizationAug 5, 2025
- CVE-2025-2532622Monitor
An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user in
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2532322Monitor
An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informati
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2532922Monitor
An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informati
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2532422Monitor
An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a c
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2532522Monitor
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2533022Monitor
An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2533122Monitor
An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2025-2533422Monitor
An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted lin
MediumCVSS 5.5No exploitEPSS 0%Feb 27, 2025
- CVE-2023-3095921Monitor
Stored XSS via javascript URI in Apollo Change Requests comment
MediumCVSS 5.4No exploitEPSS 0%palantir · apollo autopilotSep 27, 2023
- CVE-2026-6733820Monitor
JupyterLab before 4.5.9 Stored XSS via Extension Manager
MediumCVSS 5.1No exploitEPSS 0%jupyterlab · jupyterlabAug 1, 2026
- CVE-2024-4218410Monitor
HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme
LowCVSS 2.5No exploitEPSS 0%hcl software · bigfix patch management download plug-insJan 22, 2025