The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
161 vulnerabilities with CWE-184
CVE-2025-69277
MEDIUM
libsodium <ad3004e - Memory Corruption
CVSS 4.5
CVE-2025-67748
HIGH
fickling < 0.1.6 - Unsafe Pickle Misclassification via pty Module Import Bypass
CVSS 7.8
CVE-2025-67747
HIGH
fickling < 0.1.6 - Arbitrary Code Execution via Marshal and Types Module Bypass
CVSS 7.8
CVE-2025-67716
MEDIUM
Auth0 Next.js SDK <4.13.0 - Info Disclosure
CVSS 5.7
CVE-2025-61924
LOW
PrestaShop Checkout <4.4.1, 5.0.5 - Info Disclosure
CVSS 3.8
CVE-2025-58361
CRITICAL
promptcraft-forge-studio - Cross-Site Scripting via Incomplete URL Scheme Validation
CVSS 9.3
CVE-2025-58353
HIGH
promptcraft-forge-studio - Cross-Site Scripting via Regex Blacklist Bypass
CVSS 8.2
CVE-2025-48732
HIGH
WWBN AVideo 14.4 and dev master - Remote Code Execution via .phar File Request
CVSS 7.3
CVE-2025-24388
LOW
OTRS 7.0.x 8.0.x 2023.x 2024.x 2025.x and ((OTRS)) Community Edition 6.0.x - Authenticated Parameter Injection
CVSS 3.8
CVE-2025-1484
MEDIUM
Hitachi Energy Asset Suite 9.6.4.4-9.6.4.5 - Stored Cross-Site Scripting via Media Upload Component
CVSS 6.5
CVE-2025-46417
HIGH
Picklescan <0.0.25 - Info Disclosure
CVSS 7.5
CVE-2025-29822
HIGH
Microsoft Office OneNote - Info Disclosure
CVSS 7.8
CVE-2025-1716
CRITICAL
picklescan <0.0.21 - Code Injection
CVSS 9.8
CVE-2024-54149
HIGH
Winter CMS <1.2.7, 1.1.11, 1.0.476 - Auth Bypass
CVSS 8.4
CVE-2024-52595
HIGH
lxml_html_clean < 0.4.0 - Cross-Site Scripting via Improper Context-Switching Tag Handling
CVSS 7.7
CVE-2024-51745
CRITICAL
Wasmtime < 24.0.2 - Unauthenticated Filesystem Sandbox Bypass via Superscript Digit Device Filenames
CVSS 10.0
CVE-2024-32152
LOW
Anki < 24.6 - Arbitrary File Creation via LaTeX Blocklist Bypass
CVSS 3.1
CVE-2024-5217
CRITICAL
KEV
ServiceNow Washington DC and Vancouver - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-5178
MEDIUM
ServiceNow Now Platform - Sensitive File Read via Unauthorized Access
CVSS 4.9
CVE-2024-30103
HIGH
Microsoft Outlook - Remote Code Execution
CVSS 8.8
CVE-2024-23336
MEDIUM
MyBB < 1.8.38 - Server-Side Request Forgery via Incomplete Disallowed Remote Addresses List
CVSS 5.0
CVE-2024-20278
MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.5
CVE-2024-28246
MEDIUM
KaTeX 0.11.0-0.16.9 - Cross-Site Scripting via Uppercase Protocol Bypass
CVSS 5.5
CVE-2023-45593
MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 6.8
CVE-2023-45133
CRITICAL
Babel traverse <7.23.2 and 8.0.0-alpha.4 - Code Execution via path.evaluate
CVSS 9.3
Details
Vulnerabilities
161