CWE-692 · 6 records
Incomplete Denylist to Cross-Site Scripting
CVEs in this class
6 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2025-20240No exploit | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflcisco · cisco ios xe software · CWE-692 | Medium6.1 | — | 0.3% | Sep 24, 2025 |
21Monitor | CVE-2024-42214No exploit | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.hclsoftware · aftermarket epc · CWE-692 | Medium5.3 | — | 0.3% | Jul 17, 2026 |
18Monitor | CVE-2024-30924No exploit | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.derbynet · derbynet · CWE-692 | Medium4.6 | — | 0.3% | Apr 18, 2024 |
17Monitor | CVE-2024-23569No exploit | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" headerhclsoftware · aftermarket epc · CWE-692 | Medium4.3 | — | 0.3% | Jul 17, 2026 |
17Monitor | CVE-2026-15295No exploit | Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingdcooney · ajax load more – infinite scroll, load more, & lazy load · CWE-692 | Medium4.4 | — | 0.2% | Jul 10, 2026 |
11Monitor | CVE-2025-49590No exploit | CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerabilityxwiki · cryptpad · CWE-692 | Low2.9 | — | 0.3% | Jun 18, 2025 |
- CVE-2025-2024024Monitor
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl
MediumCVSS 6.1No exploitEPSS 0%cisco · cisco ios xe softwareSep 24, 2025
- CVE-2024-4221421Monitor
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.
MediumCVSS 5.3No exploitEPSS 0%hclsoftware · aftermarket epcJul 17, 2026
- CVE-2024-3092418Monitor
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
MediumCVSS 4.6No exploitEPSS 0%derbynet · derbynetApr 18, 2024
- CVE-2024-2356917Monitor
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
MediumCVSS 4.3No exploitEPSS 0%hclsoftware · aftermarket epcJul 17, 2026
- CVE-2026-1529517Monitor
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.4No exploitEPSS 0%dcooney · ajax load more – infinite scroll, load more, & lazy loadJul 10, 2026
- CVE-2025-4959011Monitor
CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
LowCVSS 2.9No exploitEPSS 0%xwiki · cryptpadJun 18, 2025