CWE-791 · 37 kayıt
Incomplete Filtering of Special Elements
Bu sınıftaki CVE’ler
37 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-2132İstismar yok | A permissive list of allowed inputs flaw was found in DPDK.dpdk · data plane development kit · CWE-791 | Yüksek8,6 | — | %2,2 | 31 Ağu 2022 |
35İzleyin | CVE-2024-47590İstismar yok | Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatchersap_se · sap web dispatcher · CWE-791 | Yüksek8,8 | — | %0,8 | 11 Kas 2024 |
35İzleyin | CVE-2025-0324Kavram kanıtı | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.axis · axis os · CWE-791 | Yüksek8,8 | — | %0,4 | 2 Haz 2025 |
34İzleyin | CVE-2026-44232İstismar yok | dssrf: every IPv6 category bypasses is_url_safehackingrepo · dssrf-js · CWE-791 | Yüksek8,7 | — | %0,5 | 12 May 2026 |
34İzleyin | CVE-2024-39283İstismar yok | Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user tointel · tdx module · CWE-791 | Yüksek8,5 | — | %0,2 | 14 Ağu 2024 |
34İzleyin | CVE-2024-45481İstismar yok | Improper authentication in SSH of B&R APROLb&r industrial automation · b&r aprol · CWE-791 | Yüksek8,5 | — | %0,1 | 25 Mar 2025 |
30İzleyin | CVE-2026-11998İstismar yok | AngularJS XSS via SCE resource URL sanitization bypassgoogle · angularjs · CWE-791 | Yüksek7,6 | — | %0,5 | 24 Haz 2026 |
29İzleyin | CVE-2023-31172İstismar yok | Incomplete Filtering of Special Elementsselinc · sel-5030 acselerator quickset · CWE-791 | Yüksek7,4 | — | %0,3 | 31 Ağu 2023 |
27İzleyin | CVE-2026-86206Kavram kanıtı | Access control filter bypass allows unauthorised access to APIsn-able · n-central · CWE-791 | Orta6,9 | — | %1,1 | 5 Eyl 2026 |
25İzleyin | CVE-2025-59303İstismar yok | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with haproxy · haproxy kubernetes ingress controller · CWE-791 | Orta6,4 | — | %0,3 | 8 Eki 2025 |
22İzleyin | CVE-2025-6761İstismar yok | Kingdee Cloud-Starry-Sky Enterprise Edition Freemarker Engine DynamicForm 4 Action.class plugin.buildMobilePopHtml special elements used in a template enginekingdee · cloud-starry-sky enterprise edition · CWE-791 | Orta5,5 | — | %0,4 | 27 Haz 2025 |
22İzleyin | CVE-2023-1076İstismar yok | A flaw was found in the Linux Kernel.linux · linux kernel · CWE-791 | Orta5,5 | — | %0,3 | 27 Mar 2023 |
22İzleyin | GHSA-vjgj-42f6-7997İstismar yok | netfoil's optional seccomp sandboxing was not appliedGo · github.com/tinfoil-factory/netfoil · CWE-791 | Orta5,5 | — | — | 29 Nis 2026 |
21İzleyin | CVE-2025-5325İstismar yok | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template enginezhilink · adp application developer platform · CWE-791 | Orta5,3 | — | %0,5 | 29 May 2025 |
21İzleyin | CVE-2025-2040İstismar yok | zhijiantianya ruoyi-vue-pro deploy special elements used in a template engineiocoder · ruoyi-vue-pro · CWE-791 | Orta5,3 | — | %0,5 | 6 Mar 2025 |
21İzleyin | CVE-2020-36827İstismar yok | The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.CWE-791 | Orta5,4 | — | %0,3 | 23 Mar 2024 |
20İzleyin | CVE-2026-3714İstismar yok | OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engineopencart · opencart · CWE-791 | Orta5,1 | — | %0,5 | 8 Mar 2026 |
19İzleyin | CVE-2025-3841İstismar yok | wix-incubator jam Jinja2 Template jam.py special elements used in a template enginewix · jam · CWE-791 | Orta4,8 | — | %0,4 | 21 Nis 2025 |
19İzleyin | CVE-2025-0716İstismar yok | AngularJS improper sanitization in SVG '<image>' elementgoogle · angularjs · CWE-791 | Orta4,8 | — | %0,4 | 29 Nis 2025 |
19İzleyin | CVE-2025-2336İstismar yok | AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'google · angularjs · CWE-791 | Orta4,8 | — | %0,3 | 4 Haz 2025 |
17İzleyin | CVE-2024-8373İstismar yok | AngularJS improper sanitization in '<source>' elementangularjs · angularjs · CWE-791 | Orta4,3 | — | %0,6 | 9 Eyl 2024 |
17İzleyin | CVE-2024-32162İstismar yok | CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.cmseasy · cmseasy · CWE-791 | Orta4,3 | — | %0,4 | 17 Nis 2024 |
8İzleyin | CVE-2026-2969İstismar yok | datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template enginedatapizza · datapizza ai · CWE-791 | Düşük2,0 | — | %0,8 | 23 Şub 2026 |
8İzleyin | CVE-2026-3725İstismar yok | 1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template enginelab1024 · smartadmin · CWE-791 | Düşük2,1 | — | %0,6 | 8 Mar 2026 |
8İzleyin | CVE-2026-19929İstismar yok | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engineCWE-791 | Düşük2,1 | — | %0,5 | 15 Ağu 2026 |
- CVE-2022-213235İzleyin
A permissive list of allowed inputs flaw was found in DPDK.
YüksekCVSS 8,6İstismar yokEPSS %2dpdk · data plane development kit31 Ağu 2022
- CVE-2024-4759035İzleyin
Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher
YüksekCVSS 8,8İstismar yokEPSS %1sap_se · sap web dispatcher11 Kas 2024
- CVE-2025-032435İzleyin
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
YüksekCVSS 8,8Kavram kanıtıEPSS %0axis · axis os2 Haz 2025
- CVE-2026-4423234İzleyin
dssrf: every IPv6 category bypasses is_url_safe
YüksekCVSS 8,7İstismar yokEPSS %0hackingrepo · dssrf-js12 May 2026
- CVE-2024-3928334İzleyin
Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to
YüksekCVSS 8,5İstismar yokEPSS %0intel · tdx module14 Ağu 2024
- CVE-2024-4548134İzleyin
Improper authentication in SSH of B&R APROL
YüksekCVSS 8,5İstismar yokEPSS %0b&r industrial automation · b&r aprol25 Mar 2025
- CVE-2026-1199830İzleyin
AngularJS XSS via SCE resource URL sanitization bypass
YüksekCVSS 7,6İstismar yokEPSS %1google · angularjs24 Haz 2026
- CVE-2023-3117229İzleyin
Incomplete Filtering of Special Elements
YüksekCVSS 7,4İstismar yokEPSS %0selinc · sel-5030 acselerator quickset31 Ağu 2023
- CVE-2026-8620627İzleyin
Access control filter bypass allows unauthorised access to APIs
OrtaCVSS 6,9Kavram kanıtıEPSS %1n-able · n-central5 Eyl 2026
- CVE-2025-5930325İzleyin
HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with
OrtaCVSS 6,4İstismar yokEPSS %0haproxy · haproxy kubernetes ingress controller8 Eki 2025
- CVE-2025-676122İzleyin
Kingdee Cloud-Starry-Sky Enterprise Edition Freemarker Engine DynamicForm 4 Action.class plugin.buildMobilePopHtml special elements used in a template engine
OrtaCVSS 5,5İstismar yokEPSS %0kingdee · cloud-starry-sky enterprise edition27 Haz 2025
- CVE-2023-107622İzleyin
A flaw was found in the Linux Kernel.
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel27 Mar 2023
- GHSA-vjgj-42f6-799722İzleyin
netfoil's optional seccomp sandboxing was not applied
OrtaCVSS 5,5İstismar yokGo · github.com/tinfoil-factory/netfoil29 Nis 2026
- CVE-2025-532521İzleyin
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testService special elements used in a template engine
OrtaCVSS 5,3İstismar yokEPSS %0zhilink · adp application developer platform29 May 2025
- CVE-2025-204021İzleyin
zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine
OrtaCVSS 5,3İstismar yokEPSS %0iocoder · ruoyi-vue-pro6 Mar 2025
- CVE-2020-3682721İzleyin
The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.
OrtaCVSS 5,4İstismar yokEPSS %023 Mar 2024
- CVE-2026-371420İzleyin
OpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engine
OrtaCVSS 5,1İstismar yokEPSS %0opencart · opencart8 Mar 2026
- CVE-2025-384119İzleyin
wix-incubator jam Jinja2 Template jam.py special elements used in a template engine
OrtaCVSS 4,8İstismar yokEPSS %0wix · jam21 Nis 2025
- CVE-2025-071619İzleyin
AngularJS improper sanitization in SVG '<image>' element
OrtaCVSS 4,8İstismar yokEPSS %0google · angularjs29 Nis 2025
- CVE-2025-233619İzleyin
AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'
OrtaCVSS 4,8İstismar yokEPSS %0google · angularjs4 Haz 2025
- CVE-2024-837317İzleyin
AngularJS improper sanitization in '<source>' element
OrtaCVSS 4,3İstismar yokEPSS %1angularjs · angularjs9 Eyl 2024
- CVE-2024-3216217İzleyin
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.
OrtaCVSS 4,3İstismar yokEPSS %0cmseasy · cmseasy17 Nis 2024
- CVE-2026-29698İzleyin
datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template engine
DüşükCVSS 2,0İstismar yokEPSS %1datapizza · datapizza ai23 Şub 2026
- CVE-2026-37258İzleyin
1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template engine
DüşükCVSS 2,1İstismar yokEPSS %1lab1024 · smartadmin8 Mar 2026
- CVE-2026-199298İzleyin
OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine
DüşükCVSS 2,1İstismar yokEPSS %015 Ağu 2026