CWE-838 · 13 kayıt
Inappropriate Encoding for Output Context
Bu sınıftaki CVE’ler
13 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-18981İstismar yok | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.pimcore · pimcore · CWE-838 | Kritik9,8 | — | %1,4 | 15 Kas 2019 |
39İzleyin | CVE-2025-4052İstismar yok | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage ingoogle · chrome · CWE-838 | Kritik9,8 | — | %0,6 | 5 May 2025 |
33İzleyin | CVE-2019-6110Kavram kanıtı | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) openbsd · openssh · CWE-838 | Orta6,8 | — | %20,9 | 31 Oca 2019 |
31İzleyin | CVE-2018-9862İstismar yok | util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of anhyper · runv · CWE-838 | Yüksek7,8 | — | %0,4 | 9 Nis 2018 |
30İzleyin | CVE-2024-11702İstismar yok | Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-basemozilla · firefox · CWE-838 | Yüksek7,5 | — | %0,5 | 26 Kas 2024 |
26İzleyin | CVE-2023-6512İstismar yok | Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the cogoogle · chrome · CWE-838 | Orta6,5 | — | %1,3 | 5 Ara 2023 |
23İzleyin | CVE-2026-55858İstismar yok | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb-java-clientmariadb-corporation · mariadb-connector-j · CWE-838 | Orta5,9 | — | %0,9 | 28 Ağu 2026 |
21İzleyin | CVE-2023-5770İstismar yok | HTML injection in email body through email subjectproofpoint · enterprise protection · CWE-838 | Orta5,4 | — | %0,3 | 9 Oca 2024 |
17İzleyin | CVE-2020-7292İstismar yok | Web Gateway (MWG) - Inappropriate Encoding for output contextmcafee · web gateway · CWE-838 | Orta4,3 | — | %0,9 | 15 Tem 2020 |
17İzleyin | CVE-2023-3735İstismar yok | Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate segoogle · chrome · CWE-838 | Orta4,3 | — | %0,6 | 1 Ağu 2023 |
17İzleyin | CVE-2024-34006İstismar yok | moodle: unsanitized HTML in site log for config_log_createdmoodle · moodle · CWE-838 | Orta4,3 | — | %0,4 | 31 May 2024 |
16İzleyin | CVE-2020-29135İstismar yok | cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).cpanel · cpanel · CWE-838 | Orta4,1 | — | %0,6 | 26 Kas 2020 |
8İzleyin | CVE-2026-47079İstismar yok | Round-trip Corruption via Improper Entity Escaping in xml_builderjoshnuss · xml_builder · CWE-838 | Düşük2,1 | — | %0,2 | 21 Ağu 2026 |
- CVE-2019-1898139İzleyin
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
KritikCVSS 9,8İstismar yokEPSS %1pimcore · pimcore15 Kas 2019
- CVE-2025-405239İzleyin
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in
KritikCVSS 9,8İstismar yokEPSS %1google · chrome5 May 2025
- CVE-2019-611033İzleyin
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker)
OrtaCVSS 6,8Kavram kanıtıEPSS %21openbsd · openssh31 Oca 2019
- CVE-2018-986231İzleyin
util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an
YüksekCVSS 7,8İstismar yokEPSS %0hyper · runv9 Nis 2018
- CVE-2024-1170230İzleyin
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-base
YüksekCVSS 7,5İstismar yokEPSS %1mozilla · firefox26 Kas 2024
- CVE-2023-651226İzleyin
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the co
OrtaCVSS 6,5İstismar yokEPSS %1google · chrome5 Ara 2023
- CVE-2026-5585823İzleyin
MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb-java-client
OrtaCVSS 5,9İstismar yokEPSS %1mariadb-corporation · mariadb-connector-j28 Ağu 2026
- CVE-2023-577021İzleyin
HTML injection in email body through email subject
OrtaCVSS 5,4İstismar yokEPSS %0proofpoint · enterprise protection9 Oca 2024
- CVE-2020-729217İzleyin
Web Gateway (MWG) - Inappropriate Encoding for output context
OrtaCVSS 4,3İstismar yokEPSS %1mcafee · web gateway15 Tem 2020
- CVE-2023-373517İzleyin
Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate se
OrtaCVSS 4,3İstismar yokEPSS %1google · chrome1 Ağu 2023
- CVE-2024-3400617İzleyin
moodle: unsanitized HTML in site log for config_log_created
OrtaCVSS 4,3İstismar yokEPSS %0moodle · moodle31 May 2024
- CVE-2020-2913516İzleyin
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
OrtaCVSS 4,1İstismar yokEPSS %1cpanel · cpanel26 Kas 2020
- CVE-2026-470798İzleyin
Round-trip Corruption via Improper Entity Escaping in xml_builder
DüşükCVSS 2,1İstismar yokEPSS %0joshnuss · xml_builder21 Ağu 2026