CVEbaza.plSłownik CWECWE-86
Common Weakness Enumeration

CWE-86

Improper Neutralization of Invalid Characters in Identifiers in Web Pages

Kategoria: VariantCVE: 11
Opis

Produkt nie neutralizuje lub nieprawidłowo neutralizuje nieprawidłowe znaki lub sekwencje bajtów w środku nazw tagów, schematów URI i innych identyfikatorów. Może to prowadzić do obejścia filtrów bezpieczeństwa i wykonania złośliwego kodu.

Description (EN)

The product does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.

Podatności CVE z CWE-86 (11)
9.0
CVSS
CRITICAL
CVE-2023-31126

Biblioteka `org.xwiki.commons:xwiki-commons-xml` używana przez platformę XWiki zawiera podatność XSS w sanitizerze HTML, który niepoprawnie waliduje atrybuty data. Pozwala to atakującemu na wstrzyknięcie dowolnego kodu HTML, co może prowadzić do przejęcia sesji użytkownika lub wykonania złośliwych skryptów w kontekście aplikacji.

pub. 2023-05-09
7.8
CVSS
HIGH
CVE-2024-21864

Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.

pub. 2024-05-16
7.2
CVSS
HIGH
CVE-2021-33158

Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

pub. 2024-02-23
6.5
CVSS
MEDIUM
CVE-2024-10941

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

pub. 2024-11-06
6.1
CVSS
MEDIUM
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.

pub. 2026-08-06
5.4
CVSS
MEDIUM
CVE-2025-20166

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

pub. 2025-01-08
5.4
CVSS
MEDIUM
CVE-2025-20167

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

pub. 2025-01-08
5.4
CVSS
MEDIUM
CVE-2025-20168

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

pub. 2025-01-08
4.4
CVSS
MEDIUM
CVE-2026-28417

Vim to edytor tekstu open source działający w linii poleceń. W wersjach przed 9.2.0073 istnieje luka command injection w standardowej wtyczce `netrw` dołączonej do Vima. Atakujący może wykonać dowolne polecenia shell z uprawnieniami procesu Vima, nakłaniając użytkownika do otwarcia spreparowanego URL-a (np. przy użyciu protokołu `scp://`). Wersja 9.2.0073 naprawia ten problem.

pub. 2026-02-27
3.3
CVSS
LOW
CVE-2023-22840

Nieprawidłowa neutralizacja w oprogramowaniu Intel(R) oneVPL GPU w wersjach poniżej 22.6.5 może pozwolić uwierzytelnionemu użytkownikowi na potencjalne uruchomienie ataku denial of service poprzez dostęp lokalny.

pub. 2023-08-11
2.1
CVSS
LOW
CVE-2025-66606

W produkcie FAST/TOOLS dostarczanym przez Yokogawa Electric Corporation odkryto lukę w zabezpieczeniach związaną z niewłaściwym kodowaniem adresów URL. Atakujący mógłby manipulować stronami internetowymi lub wykonywać złośliwe skrypty. Podatne są wersje FAST/TOOLS (pakiety: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) od R9.01 do R10.04.

pub. 2026-02-09
Informacje
ID: CWE-86
Typ: Variant
Podatności: 11
MITRE CWE ↗
← Słownik CWE