The product does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.
Volume of CVEs assigned to CWE-86 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28417HIGH Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducin | Feb 27, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-66606CRITICAL A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
This product does not
properly encode URLs. An attacker could tamper with web pages or ex | Feb 9, 2026 | 9.6 | 28 | NO | NO |
CVE-2023-31126CRITICAL `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of ar | May 9, 2023 | 9.6 | 28 | NO | NO |
CVE-2024-21864HIGH Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of p | May 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-10941MEDIUM A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126. | Nov 6, 2024 | 6.5 | 19 | NO | NO |
CVE-2025-20167MEDIUM A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripti | Jan 8, 2025 | 5.4 | 18 | NO | NO |
CVE-2021-33158HIGH Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation | Feb 23, 2024 | 7.2 | 18 | NO | NO |
CVE-2025-20168MEDIUM A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripti | Jan 8, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-20166MEDIUM A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripti | Jan 8, 2025 | 5.4 | 17 | NO | NO |
CVE-2023-22840MEDIUM Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local acc | Aug 11, 2023 | 5.5 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.