CWE-86 · 10 записей
Improper Neutralization of Invalid Characters in Identifiers in Web Pages
CVE этого класса
10 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2023-31126Proof of concept | Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xmlxwiki · xwiki · CWE-86 | Критическая9,6 | — | 0,8 % | 9 мая 2023 г. |
31Наблюдать | CVE-2026-28417Эксплойта нет | Vim has OS Command Injection in netrwvim · vim · CWE-86 | Высокая7,8 | — | 1,4 % | 27 февр. 2026 г. |
31Наблюдать | CVE-2024-21864Эксплойта нет | Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated usCWE-86 | Высокая7,8 | — | 0,3 % | 16 мая 2024 г. |
28Наблюдать | CVE-2021-33158Эксплойта нет | Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privilegintel · ethernet controller i225-it firmware · CWE-86 | Высокая7,2 | — | 0,2 % | 23 февр. 2024 г. |
26Наблюдать | CVE-2024-10941Эксплойта нет | A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.mozilla · firefox · CWE-86 | Средняя6,5 | — | 0,4 % | 6 нояб. 2024 г. |
22Наблюдать | CVE-2023-22840Эксплойта нет | Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentiallintel · onevpl gpu runtime · CWE-86 | Средняя5,5 | — | 0,4 % | 10 авг. 2023 г. |
21Наблюдать | CVE-2025-20166Эксплойта нет | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Средняя5,4 | — | 0,4 % | 8 янв. 2025 г. |
21Наблюдать | CVE-2025-20167Эксплойта нет | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Средняя5,4 | — | 0,3 % | 8 янв. 2025 г. |
21Наблюдать | CVE-2025-20168Эксплойта нет | Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilitycisco · crosswork network controller · CWE-86 | Средняя5,4 | — | 0,3 % | 8 янв. 2025 г. |
8Наблюдать | CVE-2025-66606Эксплойта нет | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.yokogawa · fast\/tools · CWE-86 | Низкая2,1 | — | 0,2 % | 9 февр. 2026 г. |
- CVE-2023-3112638Наблюдать
Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml
КритическаяCVSS 9,6Proof of conceptEPSS 1 %xwiki · xwiki9 мая 2023 г.
- CVE-2026-2841731Наблюдать
Vim has OS Command Injection in netrw
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %vim · vim27 февр. 2026 г.
- CVE-2024-2186431Наблюдать
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated us
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %16 мая 2024 г.
- CVE-2021-3315828Наблюдать
Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileg
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %intel · ethernet controller i225-it firmware23 февр. 2024 г.
- CVE-2024-1094126Наблюдать
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %mozilla · firefox6 нояб. 2024 г.
- CVE-2023-2284022Наблюдать
Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentiall
СредняяCVSS 5,5Эксплойта нетEPSS 0 %intel · onevpl gpu runtime10 авг. 2023 г.
- CVE-2025-2016621Наблюдать
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cisco · crosswork network controller8 янв. 2025 г.
- CVE-2025-2016721Наблюдать
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cisco · crosswork network controller8 янв. 2025 г.
- CVE-2025-2016821Наблюдать
Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cisco · crosswork network controller8 янв. 2025 г.
- CVE-2025-666068Наблюдать
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %yokogawa · fast\/tools9 февр. 2026 г.