CWE-86 · 10 records
Improper Neutralization of Invalid Characters in Identifiers in Web Pages
CVEs in this class
10 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2023-31126Proof of concept | Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xmlxwiki · xwiki · CWE-86 | Critical9.6 | — | 0.8% | May 9, 2023 |
31Monitor | CVE-2026-28417No exploit | Vim has OS Command Injection in netrwvim · vim · CWE-86 | High7.8 | — | 1.4% | Feb 27, 2026 |
31Monitor | CVE-2024-21864No exploit | Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated usCWE-86 | High7.8 | — | 0.3% | May 16, 2024 |
28Monitor | CVE-2021-33158No exploit | Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privilegintel · ethernet controller i225-it firmware · CWE-86 | High7.2 | — | 0.2% | Feb 23, 2024 |
26Monitor | CVE-2024-10941No exploit | A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.mozilla · firefox · CWE-86 | Medium6.5 | — | 0.4% | Nov 6, 2024 |
22Monitor | CVE-2023-22840No exploit | Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentiallintel · onevpl gpu runtime · CWE-86 | Medium5.5 | — | 0.4% | Aug 10, 2023 |
21Monitor | CVE-2025-20166No exploit | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Medium5.4 | — | 0.4% | Jan 8, 2025 |
21Monitor | CVE-2025-20167No exploit | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Medium5.4 | — | 0.3% | Jan 8, 2025 |
21Monitor | CVE-2025-20168No exploit | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Medium5.4 | — | 0.3% | Jan 8, 2025 |
8Monitor | CVE-2025-66606No exploit | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.yokogawa · fast\/tools · CWE-86 | Low2.1 | — | 0.2% | Feb 9, 2026 |
- CVE-2023-3112638Monitor
Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml
CriticalCVSS 9.6Proof of conceptEPSS 1%xwiki · xwikiMay 9, 2023
- CVE-2026-2841731Monitor
Vim has OS Command Injection in netrw
HighCVSS 7.8No exploitEPSS 1%vim · vimFeb 27, 2026
- CVE-2024-2186431Monitor
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated us
HighCVSS 7.8No exploitEPSS 0%May 16, 2024
- CVE-2021-3315828Monitor
Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileg
HighCVSS 7.2No exploitEPSS 0%intel · ethernet controller i225-it firmwareFeb 23, 2024
- CVE-2024-1094126Monitor
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.
MediumCVSS 6.5No exploitEPSS 0%mozilla · firefoxNov 6, 2024
- CVE-2023-2284022Monitor
Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentiall
MediumCVSS 5.5No exploitEPSS 0%intel · onevpl gpu runtimeAug 10, 2023
- CVE-2025-2016621Monitor
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
MediumCVSS 5.4No exploitEPSS 0%cisco · crosswork network controllerJan 8, 2025
- CVE-2025-2016721Monitor
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
MediumCVSS 5.4No exploitEPSS 0%cisco · crosswork network controllerJan 8, 2025
- CVE-2025-2016821Monitor
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
MediumCVSS 5.4No exploitEPSS 0%cisco · crosswork network controllerJan 8, 2025
- CVE-2025-666068Monitor
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
LowCVSS 2.1No exploitEPSS 0%yokogawa · fast\/toolsFeb 9, 2026