CWE-84
CVEs classified under CWE-84, newest first.
3 CVEsRSS
CVE-2026-88859Medium· 6.3A flaw was found in Evolution
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler in…
▾ SunlitRed Hat · evolutionEPSS 0.32%via NVD
CVE-2026-67338Medium· 6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in p…
▾ Sunlitjupyterlab · jupyterlabEPSS 0.17%via NVD
GHSA-vmhf-c436-hxj4MediumJupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
▾ Sunlitjupyterlab · jupyterlabvia GHSA