İçeriğe atla
Noroxi

CWE-692 · 6 kayıt

Incomplete Denylist to Cross-Site Scripting

Bu sınıftaki CVE’ler

6 kayıt

  • CVE-2025-20240
    24İzleyin

    A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a refl

    OrtaCVSS 6,1İstismar yokEPSS %0

    cisco · cisco ios xe software24 Eyl 2025

  • CVE-2024-42214
    21İzleyin

    HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.

    OrtaCVSS 5,3İstismar yokEPSS %0

    hclsoftware · aftermarket epc17 Tem 2026

  • CVE-2024-30924
    18İzleyin

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

    OrtaCVSS 4,6İstismar yokEPSS %0

    derbynet · derbynet18 Nis 2024

  • CVE-2024-23569
    17İzleyin

    HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

    OrtaCVSS 4,3İstismar yokEPSS %0

    hclsoftware · aftermarket epc17 Tem 2026

  • CVE-2026-15295
    17İzleyin

    Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    OrtaCVSS 4,4İstismar yokEPSS %0

    dcooney · ajax load more – infinite scroll, load more, & lazy load10 Tem 2026

  • CVE-2025-49590
    11İzleyin

    CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability

    DüşükCVSS 2,9İstismar yokEPSS %0

    xwiki · cryptpad18 Haz 2025

Tüm zafiyet sınıfları