CVEs classified under CWE-692, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2025-20240 — CVSS 6.1 (medium): A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a…
CVE-2025-49590 — CVSS 6.1 (medium): CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to…
CVE-2024-42214 — CVSS 5.3 (medium): HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of…
CVE-2024-30924 — CVSS 4.6 (medium): Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
CVE-2026-15295 — CVSS 4.4 (medium): The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in…
CVE-2024-23569 — CVSS 4.3 (medium): HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header