Перейти к содержимому
Noroxi

CWE-692 · 6 записей

Incomplete Denylist to Cross-Site Scripting

CVE этого класса

6 записей

  • CVE-2025-20240
    24Наблюдать

    A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    cisco · cisco ios xe software24 сент. 2025 г.

  • CVE-2024-42214
    21Наблюдать

    HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    hclsoftware · aftermarket epc17 июл. 2026 г.

  • CVE-2024-30924
    18Наблюдать

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    derbynet · derbynet18 апр. 2024 г.

  • CVE-2024-23569
    17Наблюдать

    HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    hclsoftware · aftermarket epc17 июл. 2026 г.

  • CVE-2026-15295
    17Наблюдать

    Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    dcooney · ajax load more – infinite scroll, load more, & lazy load10 июл. 2026 г.

  • CVE-2025-49590
    11Наблюдать

    CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability

    НизкаяCVSS 2,9Эксплойта нетEPSS 0 %

    xwiki · cryptpad18 июн. 2025 г.

Все классы уязвимостей