Skip to main content

CWE archive

CWE-692 CVEs

Programmatic archive

9 CVEs tagged with CWE-6920 Critical, 0 High, 7 Medium, 2 Low, 0 Unrated.

CVE-2024-42214

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the We…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23569

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15295

Published Jul 10, 2026

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-20240

Published Sep 24, 2025

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS)…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-53904

Published Jul 16, 2025

The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-…

CVSS 1.3 · Low

CVE-2025-49590

Published Jun 18, 2025

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however th…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52305

Published Nov 13, 2024

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30924

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26047

Published Mar 3, 2023

teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1