Skip to main content

CWE archive

CWE-86 CVEs

Programmatic archive

10 CVEs tagged with CWE-861 Critical, 2 High, 5 Medium, 2 Low, 0 Unrated.

CVE-2026-28417

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By induci…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-66606

Published Feb 9, 2026

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or e…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10941

Published Nov 6, 2024

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21864

Published May 16, 2024

Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of…

CVSS 7.8 · High

CVE-2021-33158

Published Feb 23, 2024

Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalatio…

CVSS 7.2 · High

CVE-2023-31126

Published May 9, 2023

`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1