CWE-84 · 19 kayıt
Improper Neutralization of Encoded URI Schemes in a Web Page
Bu sınıftaki CVE’ler
19 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2025-58444İstismar yok | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Servermodelcontextprotocol · inspector · CWE-84 | Yüksek8,6 | — | %0,7 | 8 Eyl 2025 |
33İzleyin | CVE-2022-40181İstismar yok | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Dsiemens · desigo pxm30-1 firmware · CWE-84 | Yüksek8,3 | — | %0,9 | 11 Eki 2022 |
27İzleyin | CVE-2026-96654İstismar yok | Plex Media Server URL injectionplex · media server · CWE-84 | Orta6,9 | — | %0,2 | 6 gün önce |
25İzleyin | CVE-2026-88859İstismar yok | Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restrictionred hat · red hat enterprise linux 6 · CWE-84 | Orta6,3 | — | %0,5 | 10 Eyl 2026 |
24İzleyin | CVE-2020-7011İstismar yok | Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.elastic · elastic app search · CWE-84 | Orta6,1 | — | %1,0 | 3 Haz 2020 |
24İzleyin | CVE-2021-3824İstismar yok | OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.openvpn · openvpn access server · CWE-84 | Orta6,1 | — | %0,7 | 23 Eyl 2021 |
24İzleyin | CVE-2024-45045İstismar yok | JavaScript Injection via url encoded values in links in Collabora Office Androidcollabora · online · CWE-84 | Orta6,1 | — | %0,3 | 29 Ağu 2024 |
24İzleyin | CVE-2024-52890İstismar yok | IBM Engineering Lifecycle Optimization - Publishing cross-site scriptingibm · engineering lifecycle optimization · CWE-84 | Orta6,1 | — | %0,2 | 5 Ağu 2025 |
22İzleyin | CVE-2025-25326İstismar yok | An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user inCWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25323İstismar yok | An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informatiCWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25329İstismar yok | An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informatiCWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25324İstismar yok | An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a cCWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25325İstismar yok | An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via CWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25330İstismar yok | An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.CWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25331İstismar yok | An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.CWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
22İzleyin | CVE-2025-25334İstismar yok | An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted linCWE-84 | Orta5,5 | — | %0,2 | 27 Şub 2025 |
21İzleyin | CVE-2023-30959İstismar yok | Stored XSS via javascript URI in Apollo Change Requests commentpalantir · apollo autopilot · CWE-84 | Orta5,4 | — | %0,4 | 27 Eyl 2023 |
20İzleyin | CVE-2026-67338İstismar yok | JupyterLab before 4.5.9 Stored XSS via Extension Managerjupyterlab · jupyterlab · CWE-84 | Orta5,1 | — | %0,3 | 1 Ağu 2026 |
10İzleyin | CVE-2024-42184İstismar yok | HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI schemehcl software · bigfix patch management download plug-ins · CWE-84 | Düşük2,5 | — | %0,1 | 22 Oca 2025 |
- CVE-2025-5844434İzleyin
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
YüksekCVSS 8,6İstismar yokEPSS %1modelcontextprotocol · inspector8 Eyl 2025
- CVE-2022-4018133İzleyin
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), D
YüksekCVSS 8,3İstismar yokEPSS %1siemens · desigo pxm30-1 firmware11 Eki 2022
- CVE-2026-9665427İzleyin
Plex Media Server URL injection
OrtaCVSS 6,9İstismar yokEPSS %0plex · media server6 gün önce
- CVE-2026-8885925İzleyin
Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction
OrtaCVSS 6,3İstismar yokEPSS %1red hat · red hat enterprise linux 610 Eyl 2026
- CVE-2020-701124İzleyin
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.
OrtaCVSS 6,1İstismar yokEPSS %1elastic · elastic app search3 Haz 2020
- CVE-2021-382424İzleyin
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
OrtaCVSS 6,1İstismar yokEPSS %1openvpn · openvpn access server23 Eyl 2021
- CVE-2024-4504524İzleyin
JavaScript Injection via url encoded values in links in Collabora Office Android
OrtaCVSS 6,1İstismar yokEPSS %0collabora · online29 Ağu 2024
- CVE-2024-5289024İzleyin
IBM Engineering Lifecycle Optimization - Publishing cross-site scripting
OrtaCVSS 6,1İstismar yokEPSS %0ibm · engineering lifecycle optimization5 Ağu 2025
- CVE-2025-2532622İzleyin
An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user in
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2532322İzleyin
An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informati
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2532922İzleyin
An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informati
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2532422İzleyin
An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a c
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2532522İzleyin
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2533022İzleyin
An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2533122İzleyin
An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2025-2533422İzleyin
An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted lin
OrtaCVSS 5,5İstismar yokEPSS %027 Şub 2025
- CVE-2023-3095921İzleyin
Stored XSS via javascript URI in Apollo Change Requests comment
OrtaCVSS 5,4İstismar yokEPSS %0palantir · apollo autopilot27 Eyl 2023
- CVE-2026-6733820İzleyin
JupyterLab before 4.5.9 Stored XSS via Extension Manager
OrtaCVSS 5,1İstismar yokEPSS %0jupyterlab · jupyterlab1 Ağu 2026
- CVE-2024-4218410İzleyin
HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme
DüşükCVSS 2,5İstismar yokEPSS %0hcl software · bigfix patch management download plug-ins22 Oca 2025