Skip to content
Noroxi

CWE-86 · 10 records

Improper Neutralization of Invalid Characters in Identifiers in Web Pages

CVEs in this class

10 records

  • Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml

    CriticalCVSS 9.6Proof of conceptEPSS 1%

    xwiki · xwikiMay 9, 2023

  • Vim has OS Command Injection in netrw

    HighCVSS 7.8No exploitEPSS 1%

    vim · vimFeb 27, 2026

  • Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated us

    HighCVSS 7.8No exploitEPSS 0%

    May 16, 2024

  • Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileg

    HighCVSS 7.2No exploitEPSS 0%

    intel · ethernet controller i225-it firmwareFeb 23, 2024

  • A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.

    MediumCVSS 6.5No exploitEPSS 0%

    mozilla · firefoxNov 6, 2024

  • Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentiall

    MediumCVSS 5.5No exploitEPSS 0%

    intel · onevpl gpu runtimeAug 10, 2023

  • Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    cisco · crosswork network controllerJan 8, 2025

  • Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    cisco · crosswork network controllerJan 8, 2025

  • Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    cisco · crosswork network controllerJan 8, 2025

  • A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.

    LowCVSS 2.1No exploitEPSS 0%

    yokogawa · fast\/toolsFeb 9, 2026

All vulnerability classes