CWE-692 · 6 kayıt
Incomplete Denylist to Cross-Site Scripting
Bu sınıftaki CVE’ler
6 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
24İzleyin | CVE-2025-20240İstismar yok | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflcisco · cisco ios xe software · CWE-692 | Orta6,1 | — | %0,3 | 24 Eyl 2025 |
21İzleyin | CVE-2024-42214İstismar yok | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.hclsoftware · aftermarket epc · CWE-692 | Orta5,3 | — | %0,3 | 17 Tem 2026 |
18İzleyin | CVE-2024-30924İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.derbynet · derbynet · CWE-692 | Orta4,6 | — | %0,3 | 18 Nis 2024 |
17İzleyin | CVE-2024-23569İstismar yok | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" headerhclsoftware · aftermarket epc · CWE-692 | Orta4,3 | — | %0,3 | 17 Tem 2026 |
17İzleyin | CVE-2026-15295İstismar yok | Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingdcooney · ajax load more – infinite scroll, load more, & lazy load · CWE-692 | Orta4,4 | — | %0,2 | 10 Tem 2026 |
11İzleyin | CVE-2025-49590İstismar yok | CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerabilityxwiki · cryptpad · CWE-692 | Düşük2,9 | — | %0,3 | 18 Haz 2025 |
- CVE-2025-2024024İzleyin
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl
OrtaCVSS 6,1İstismar yokEPSS %0cisco · cisco ios xe software24 Eyl 2025
- CVE-2024-4221421İzleyin
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.
OrtaCVSS 5,3İstismar yokEPSS %0hclsoftware · aftermarket epc17 Tem 2026
- CVE-2024-3092418İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
OrtaCVSS 4,6İstismar yokEPSS %0derbynet · derbynet18 Nis 2024
- CVE-2024-2356917İzleyin
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
OrtaCVSS 4,3İstismar yokEPSS %0hclsoftware · aftermarket epc17 Tem 2026
- CVE-2026-1529517İzleyin
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
OrtaCVSS 4,4İstismar yokEPSS %0dcooney · ajax load more – infinite scroll, load more, & lazy load10 Tem 2026
- CVE-2025-4959011İzleyin
CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
DüşükCVSS 2,9İstismar yokEPSS %0xwiki · cryptpad18 Haz 2025