VulnSea

CWE-116

CVEs classified under CWE-116, newest first.

109 CVEsRSS

CVE-2026-48598Low· 3.7PoC
3mo ago

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

▾ Twilightelixir-tesla · teslaEPSS 0.34%via NVD
CVE-2026-26028Medium· 6.1
4mo ago

CryptPad is an end-to-end encrypted collaborative office suite

CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-6019Medium· 6.1
5mo ago

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base…

▾ Sunlitpython · pythonEPSS 0.58%via NVD
CVE-2026-6058Medium· 4.5
5mo ago

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condit…

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condit…

▾ Sunlitzyxel · wre6505_firmwareEPSS 0.22%via NVD
CVE-2026-20136Medium· 6.0
5mo ago

A vulnerability in the&nbsp;CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack …

A vulnerability in the&nbsp;CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack …

▾ Sunlitcisco · identity_services_engineEPSS 0.50%via NVD
CVE-2026-34481High· 7.5
5mo ago

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN…

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN…

▾ Twilightapache · log4jEPSS 0.85%via NVD
CVE-2026-33941High· 8.2PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…

▾ Midnighthandlebarsjs · handlebarsEPSS 0.22%via NVD
CVE-2026-31898High· 8.1
6mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to p…

▾ Twilightparall · jspdfEPSS 0.62%via NVD
CVE-2026-3644High· 7.5
6mo ago

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additio…

▾ Twilightpython · pythonEPSS 0.65%via NVD
CVE-2026-25940High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

▾ Midnightparall · jspdfEPSS 0.63%via NVD
CVE-2026-25755High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …

▾ Midnightparall · jspdfEPSS 0.80%via NVD
CVE-2026-24737High· 8.1
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

▾ Twilightparall · jspdfEPSS 0.55%via NVD
CVE-2025-1795None
1y ago

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma…

▾ SunlitEPSS 0.63%via NVD
CVE-2023-48655Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-29543High· 8.8
3y ago

An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector

An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < …

▾ Twilightmozilla · firefoxEPSS 0.52%via NVD
CVE-2023-29541High· 8.8
3y ago

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating syst…

▾ Twilightmozilla · firefoxEPSS 0.74%via NVD
CVE-2022-24682Medium· 6.1CISA KEV0dayPoC
4y ago

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript insi…

▾ Midnightsynacor · zimbra_collaboration_suiteEPSS 31%via NVD
CVE-2019-12675High· 8.8
6y ago

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges…

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.73%via NVD
CVE-2019-12674High· 8.2
6y ago

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges…

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.78%via NVD
CWE-116 vulnerabilities (CVEs) — page 4 · VulnSea