CWE-692 · 6 записей
Incomplete Denylist to Cross-Site Scripting
CVE этого класса
6 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
24Наблюдать | CVE-2025-20240Эксплойта нет | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflcisco · cisco ios xe software · CWE-692 | Средняя6,1 | — | 0,3 % | 24 сент. 2025 г. |
21Наблюдать | CVE-2024-42214Эксплойта нет | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.hclsoftware · aftermarket epc · CWE-692 | Средняя5,3 | — | 0,3 % | 17 июл. 2026 г. |
18Наблюдать | CVE-2024-30924Эксплойта нет | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.derbynet · derbynet · CWE-692 | Средняя4,6 | — | 0,3 % | 18 апр. 2024 г. |
17Наблюдать | CVE-2024-23569Эксплойта нет | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" headerhclsoftware · aftermarket epc · CWE-692 | Средняя4,3 | — | 0,3 % | 17 июл. 2026 г. |
17Наблюдать | CVE-2026-15295Эксплойта нет | Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingdcooney · ajax load more – infinite scroll, load more, & lazy load · CWE-692 | Средняя4,4 | — | 0,2 % | 10 июл. 2026 г. |
11Наблюдать | CVE-2025-49590Эксплойта нет | CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerabilityxwiki · cryptpad · CWE-692 | Низкая2,9 | — | 0,3 % | 18 июн. 2025 г. |
- CVE-2025-2024024Наблюдать
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl
СредняяCVSS 6,1Эксплойта нетEPSS 0 %cisco · cisco ios xe software24 сент. 2025 г.
- CVE-2024-4221421Наблюдать
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %hclsoftware · aftermarket epc17 июл. 2026 г.
- CVE-2024-3092418Наблюдать
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
СредняяCVSS 4,6Эксплойта нетEPSS 0 %derbynet · derbynet18 апр. 2024 г.
- CVE-2024-2356917Наблюдать
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
СредняяCVSS 4,3Эксплойта нетEPSS 0 %hclsoftware · aftermarket epc17 июл. 2026 г.
- CVE-2026-1529517Наблюдать
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
СредняяCVSS 4,4Эксплойта нетEPSS 0 %dcooney · ajax load more – infinite scroll, load more, & lazy load10 июл. 2026 г.
- CVE-2025-4959011Наблюдать
CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
НизкаяCVSS 2,9Эксплойта нетEPSS 0 %xwiki · cryptpad18 июн. 2025 г.