İçeriğe atla
Noroxi

CWE-84 · 19 kayıt

Improper Neutralization of Encoded URI Schemes in a Web Page

Bu sınıftaki CVE’ler

19 kayıt

  • CVE-2025-58444
    34İzleyin

    MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

    YüksekCVSS 8,6İstismar yokEPSS %1

    modelcontextprotocol · inspector8 Eyl 2025

  • CVE-2022-40181
    33İzleyin

    A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), D

    YüksekCVSS 8,3İstismar yokEPSS %1

    siemens · desigo pxm30-1 firmware11 Eki 2022

  • CVE-2026-96654
    27İzleyin

    Plex Media Server URL injection

    OrtaCVSS 6,9İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2026-88859
    25İzleyin

    Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction

    OrtaCVSS 6,3İstismar yokEPSS %1

    red hat · red hat enterprise linux 610 Eyl 2026

  • CVE-2020-7011
    24İzleyin

    Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI.

    OrtaCVSS 6,1İstismar yokEPSS %1

    elastic · elastic app search3 Haz 2020

  • CVE-2021-3824
    24İzleyin

    OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

    OrtaCVSS 6,1İstismar yokEPSS %1

    openvpn · openvpn access server23 Eyl 2021

  • CVE-2024-45045
    24İzleyin

    JavaScript Injection via url encoded values in links in Collabora Office Android

    OrtaCVSS 6,1İstismar yokEPSS %0

    collabora · online29 Ağu 2024

  • CVE-2024-52890
    24İzleyin

    IBM Engineering Lifecycle Optimization - Publishing cross-site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    ibm · engineering lifecycle optimization5 Ağu 2025

  • CVE-2025-25326
    22İzleyin

    An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user in

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25323
    22İzleyin

    An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user informati

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25329
    22İzleyin

    An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user informati

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25324
    22İzleyin

    An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a c

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25325
    22İzleyin

    An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25330
    22İzleyin

    An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25331
    22İzleyin

    An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2025-25334
    22İzleyin

    An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted lin

    OrtaCVSS 5,5İstismar yokEPSS %0

    27 Şub 2025

  • CVE-2023-30959
    21İzleyin

    Stored XSS via javascript URI in Apollo Change Requests comment

    OrtaCVSS 5,4İstismar yokEPSS %0

    palantir · apollo autopilot27 Eyl 2023

  • CVE-2026-67338
    20İzleyin

    JupyterLab before 4.5.9 Stored XSS via Extension Manager

    OrtaCVSS 5,1İstismar yokEPSS %0

    jupyterlab · jupyterlab1 Ağu 2026

  • CVE-2024-42184
    10İzleyin

    HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme

    DüşükCVSS 2,5İstismar yokEPSS %0

    hcl software · bigfix patch management download plug-ins22 Oca 2025

Tüm zafiyet sınıfları