Перейти к содержимому
Noroxi

CWE-791 · 38 записей

Incomplete Filtering of Special Elements

CVE этого класса

39 записей

  • CVE-2022-2132
    35Наблюдать

    A permissive list of allowed inputs flaw was found in DPDK.

    ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %

    dpdk · data plane development kit31 авг. 2022 г.

  • CVE-2024-47590
    35Наблюдать

    Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sap_se · sap web dispatcher11 нояб. 2024 г.

  • CVE-2025-0324
    35Наблюдать

    The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

    ВысокаяCVSS 8,8Proof of conceptEPSS 0 %

    axis · axis os2 июн. 2025 г.

  • CVE-2026-44232
    34Наблюдать

    dssrf: every IPv6 category bypasses is_url_safe

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    hackingrepo · dssrf-js12 мая 2026 г.

  • CVE-2024-39283
    34Наблюдать

    Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    intel · tdx module14 авг. 2024 г.

  • CVE-2024-45481
    34Наблюдать

    Improper authentication in SSH of B&R APROL

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    b&r industrial automation · b&r aprol25 мар. 2025 г.

  • CVE-2026-11998
    30Наблюдать

    AngularJS XSS via SCE resource URL sanitization bypass

    ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %

    google · angularjs24 июн. 2026 г.

  • CVE-2023-31172
    29Наблюдать

    Incomplete Filtering of Special Elements

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    selinc · sel-5030 acselerator quickset31 авг. 2023 г.

  • CVE-2026-86206
    27Наблюдать

    Access control filter bypass allows unauthorised access to APIs

    СредняяCVSS 6,9Proof of conceptEPSS 1 %

    n-able · n-central5 сент. 2026 г.

  • CVE-2025-59303
    25Наблюдать

    HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    haproxy · haproxy kubernetes ingress controller8 окт. 2025 г.

  • CVE-2025-6761
    22Наблюдать

    Kingdee Cloud-Starry-Sky Enterprise Edition Freemarker Engine DynamicForm 4 Action.class plugin.buildMobilePopHtml special elements used in a template engine

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    kingdee · cloud-starry-sky enterprise edition27 июн. 2025 г.

  • CVE-2023-1076
    22Наблюдать

    A flaw was found in the Linux Kernel.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    linux · linux kernel27 мар. 2023 г.

  • GHSA-vjgj-42f6-7997
    22Наблюдать

    netfoil's optional seccomp sandboxing was not applied

    СредняяCVSS 5,5Эксплойта нет

    Go · github.com/tinfoil-factory/netfoil29 апр. 2026 г.

  • CVE-2025-5325
    21Наблюдать

    zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template engine

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    zhilink · adp application developer platform29 мая 2025 г.

  • CVE-2025-2040
    21Наблюдать

    zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    iocoder · ruoyi-vue-pro6 мар. 2025 г.

  • CVE-2020-36827
    21Наблюдать

    The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    23 мар. 2024 г.

  • CVE-2026-3714
    20Наблюдать

    OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engine

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    opencart · opencart8 мар. 2026 г.

  • CVE-2025-3841
    19Наблюдать

    wix-incubator jam Jinja2 Template jam.py special elements used in a template engine

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    wix · jam21 апр. 2025 г.

  • CVE-2025-0716
    19Наблюдать

    AngularJS improper sanitization in SVG '<image>' element

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    google · angularjs29 апр. 2025 г.

  • CVE-2025-2336
    19Наблюдать

    AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    google · angularjs4 июн. 2025 г.

  • CVE-2024-8373
    17Наблюдать

    AngularJS improper sanitization in '<source>' element

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    angularjs · angularjs9 сент. 2024 г.

  • CVE-2024-32162
    17Наблюдать

    CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    cmseasy · cmseasy17 апр. 2024 г.

  • CVE-2026-2969
    8Наблюдать

    datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template engine

    НизкаяCVSS 2,0Эксплойта нетEPSS 1 %

    datapizza · datapizza ai23 февр. 2026 г.

  • CVE-2026-3725
    8Наблюдать

    1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template engine

    НизкаяCVSS 2,1Эксплойта нетEPSS 1 %

    lab1024 · smartadmin8 мар. 2026 г.

  • CVE-2026-19929
    8Наблюдать

    OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    15 авг. 2026 г.

Все классы уязвимостей