Skip to content
Noroxi

CWE-692 · 6 records

Incomplete Denylist to Cross-Site Scripting

CVEs in this class

6 records

  • A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl

    MediumCVSS 6.1No exploitEPSS 0%

    cisco · cisco ios xe softwareSep 24, 2025

  • HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.

    MediumCVSS 5.3No exploitEPSS 0%

    hclsoftware · aftermarket epcJul 17, 2026

  • Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

    MediumCVSS 4.6No exploitEPSS 0%

    derbynet · derbynetApr 18, 2024

  • HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

    MediumCVSS 4.3No exploitEPSS 0%

    hclsoftware · aftermarket epcJul 17, 2026

  • Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    MediumCVSS 4.4No exploitEPSS 0%

    dcooney · ajax load more – infinite scroll, load more, & lazy loadJul 10, 2026

  • CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability

    LowCVSS 2.9No exploitEPSS 0%

    xwiki · cryptpadJun 18, 2025

All vulnerability classes