CWE-791 · 38 записей
Incomplete Filtering of Special Elements
CVE этого класса
39 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-2132Эксплойта нет | A permissive list of allowed inputs flaw was found in DPDK.dpdk · data plane development kit · CWE-791 | Высокая8,6 | — | 2,2 % | 31 авг. 2022 г. |
35Наблюдать | CVE-2024-47590Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatchersap_se · sap web dispatcher · CWE-791 | Высокая8,8 | — | 0,8 % | 11 нояб. 2024 г. |
35Наблюдать | CVE-2025-0324Proof of concept | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.axis · axis os · CWE-791 | Высокая8,8 | — | 0,4 % | 2 июн. 2025 г. |
34Наблюдать | CVE-2026-44232Эксплойта нет | dssrf: every IPv6 category bypasses is_url_safehackingrepo · dssrf-js · CWE-791 | Высокая8,7 | — | 0,5 % | 12 мая 2026 г. |
34Наблюдать | CVE-2024-39283Эксплойта нет | Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user tointel · tdx module · CWE-791 | Высокая8,5 | — | 0,2 % | 14 авг. 2024 г. |
34Наблюдать | CVE-2024-45481Эксплойта нет | Improper authentication in SSH of B&R APROLb&r industrial automation · b&r aprol · CWE-791 | Высокая8,5 | — | 0,1 % | 25 мар. 2025 г. |
30Наблюдать | CVE-2026-11998Эксплойта нет | AngularJS XSS via SCE resource URL sanitization bypassgoogle · angularjs · CWE-791 | Высокая7,6 | — | 0,5 % | 24 июн. 2026 г. |
29Наблюдать | CVE-2023-31172Эксплойта нет | Incomplete Filtering of Special Elementsselinc · sel-5030 acselerator quickset · CWE-791 | Высокая7,4 | — | 0,3 % | 31 авг. 2023 г. |
27Наблюдать | CVE-2026-86206Proof of concept | Access control filter bypass allows unauthorised access to APIsn-able · n-central · CWE-791 | Средняя6,9 | — | 1,1 % | 5 сент. 2026 г. |
25Наблюдать | CVE-2025-59303Эксплойта нет | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with haproxy · haproxy kubernetes ingress controller · CWE-791 | Средняя6,4 | — | 0,3 % | 8 окт. 2025 г. |
22Наблюдать | CVE-2025-6761Эксплойта нет | Kingdee Cloud-Starry-Sky Enterprise Edition Freemarker Engine DynamicForm 4 Action.class plugin.buildMobilePopHtml special elements used in a template enginekingdee · cloud-starry-sky enterprise edition · CWE-791 | Средняя5,5 | — | 0,4 % | 27 июн. 2025 г. |
22Наблюдать | CVE-2023-1076Эксплойта нет | A flaw was found in the Linux Kernel.linux · linux kernel · CWE-791 | Средняя5,5 | — | 0,3 % | 27 мар. 2023 г. |
22Наблюдать | GHSA-vjgj-42f6-7997Эксплойта нет | netfoil's optional seccomp sandboxing was not appliedGo · github.com/tinfoil-factory/netfoil · CWE-791 | Средняя5,5 | — | — | 29 апр. 2026 г. |
21Наблюдать | CVE-2025-5325Эксплойта нет | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template enginezhilink · adp application developer platform · CWE-791 | Средняя5,3 | — | 0,5 % | 29 мая 2025 г. |
21Наблюдать | CVE-2025-2040Эксплойта нет | zhijiantianya ruoyi-vue-pro deploy special elements used in a template engineiocoder · ruoyi-vue-pro · CWE-791 | Средняя5,3 | — | 0,5 % | 6 мар. 2025 г. |
21Наблюдать | CVE-2020-36827Эксплойта нет | The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.CWE-791 | Средняя5,4 | — | 0,3 % | 23 мар. 2024 г. |
20Наблюдать | CVE-2026-3714Эксплойта нет | OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engineopencart · opencart · CWE-791 | Средняя5,1 | — | 0,5 % | 8 мар. 2026 г. |
19Наблюдать | CVE-2025-3841Эксплойта нет | wix-incubator jam Jinja2 Template jam.py special elements used in a template enginewix · jam · CWE-791 | Средняя4,8 | — | 0,4 % | 21 апр. 2025 г. |
19Наблюдать | CVE-2025-0716Эксплойта нет | AngularJS improper sanitization in SVG '<image>' elementgoogle · angularjs · CWE-791 | Средняя4,8 | — | 0,4 % | 29 апр. 2025 г. |
19Наблюдать | CVE-2025-2336Эксплойта нет | AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'google · angularjs · CWE-791 | Средняя4,8 | — | 0,3 % | 4 июн. 2025 г. |
17Наблюдать | CVE-2024-8373Эксплойта нет | AngularJS improper sanitization in '<source>' elementangularjs · angularjs · CWE-791 | Средняя4,3 | — | 0,6 % | 9 сент. 2024 г. |
17Наблюдать | CVE-2024-32162Эксплойта нет | CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.cmseasy · cmseasy · CWE-791 | Средняя4,3 | — | 0,4 % | 17 апр. 2024 г. |
8Наблюдать | CVE-2026-2969Эксплойта нет | datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template enginedatapizza · datapizza ai · CWE-791 | Низкая2,0 | — | 0,8 % | 23 февр. 2026 г. |
8Наблюдать | CVE-2026-3725Эксплойта нет | 1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template enginelab1024 · smartadmin · CWE-791 | Низкая2,1 | — | 0,7 % | 8 мар. 2026 г. |
8Наблюдать | CVE-2026-19929Эксплойта нет | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engineCWE-791 | Низкая2,1 | — | 0,5 % | 15 авг. 2026 г. |
- CVE-2022-213235Наблюдать
A permissive list of allowed inputs flaw was found in DPDK.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %dpdk · data plane development kit31 авг. 2022 г.
- CVE-2024-4759035Наблюдать
Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sap_se · sap web dispatcher11 нояб. 2024 г.
- CVE-2025-032435Наблюдать
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %axis · axis os2 июн. 2025 г.
- CVE-2026-4423234Наблюдать
dssrf: every IPv6 category bypasses is_url_safe
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %hackingrepo · dssrf-js12 мая 2026 г.
- CVE-2024-3928334Наблюдать
Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %intel · tdx module14 авг. 2024 г.
- CVE-2024-4548134Наблюдать
Improper authentication in SSH of B&R APROL
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %b&r industrial automation · b&r aprol25 мар. 2025 г.
- CVE-2026-1199830Наблюдать
AngularJS XSS via SCE resource URL sanitization bypass
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %google · angularjs24 июн. 2026 г.
- CVE-2023-3117229Наблюдать
Incomplete Filtering of Special Elements
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %selinc · sel-5030 acselerator quickset31 авг. 2023 г.
- CVE-2026-8620627Наблюдать
Access control filter bypass allows unauthorised access to APIs
СредняяCVSS 6,9Proof of conceptEPSS 1 %n-able · n-central5 сент. 2026 г.
- CVE-2025-5930325Наблюдать
HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with
СредняяCVSS 6,4Эксплойта нетEPSS 0 %haproxy · haproxy kubernetes ingress controller8 окт. 2025 г.
- CVE-2025-676122Наблюдать
Kingdee Cloud-Starry-Sky Enterprise Edition Freemarker Engine DynamicForm 4 Action.class plugin.buildMobilePopHtml special elements used in a template engine
СредняяCVSS 5,5Эксплойта нетEPSS 0 %kingdee · cloud-starry-sky enterprise edition27 июн. 2025 г.
- CVE-2023-107622Наблюдать
A flaw was found in the Linux Kernel.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel27 мар. 2023 г.
- GHSA-vjgj-42f6-799722Наблюдать
netfoil's optional seccomp sandboxing was not applied
СредняяCVSS 5,5Эксплойта нетGo · github.com/tinfoil-factory/netfoil29 апр. 2026 г.
- CVE-2025-532521Наблюдать
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template engine
СредняяCVSS 5,3Эксплойта нетEPSS 1 %zhilink · adp application developer platform29 мая 2025 г.
- CVE-2025-204021Наблюдать
zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine
СредняяCVSS 5,3Эксплойта нетEPSS 0 %iocoder · ruoyi-vue-pro6 мар. 2025 г.
- CVE-2020-3682721Наблюдать
The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %23 мар. 2024 г.
- CVE-2026-371420Наблюдать
OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engine
СредняяCVSS 5,1Эксплойта нетEPSS 0 %opencart · opencart8 мар. 2026 г.
- CVE-2025-384119Наблюдать
wix-incubator jam Jinja2 Template jam.py special elements used in a template engine
СредняяCVSS 4,8Эксплойта нетEPSS 0 %wix · jam21 апр. 2025 г.
- CVE-2025-071619Наблюдать
AngularJS improper sanitization in SVG '<image>' element
СредняяCVSS 4,8Эксплойта нетEPSS 0 %google · angularjs29 апр. 2025 г.
- CVE-2025-233619Наблюдать
AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'
СредняяCVSS 4,8Эксплойта нетEPSS 0 %google · angularjs4 июн. 2025 г.
- CVE-2024-837317Наблюдать
AngularJS improper sanitization in '<source>' element
СредняяCVSS 4,3Эксплойта нетEPSS 1 %angularjs · angularjs9 сент. 2024 г.
- CVE-2024-3216217Наблюдать
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %cmseasy · cmseasy17 апр. 2024 г.
- CVE-2026-29698Наблюдать
datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template engine
НизкаяCVSS 2,0Эксплойта нетEPSS 1 %datapizza · datapizza ai23 февр. 2026 г.
- CVE-2026-37258Наблюдать
1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template engine
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %lab1024 · smartadmin8 мар. 2026 г.
- CVE-2026-199298Наблюдать
OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %15 авг. 2026 г.