Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dryice Myxalytics HIGH 8.0
CVE-2024-42176

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed f…

Mitigation only
Fix from $1,950 2025-03-19
Hcl Sx MEDIUM 5.7
CVE-2024-30154

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit…

Mitigation only
Fix from $1,600 2025-03-03
Dryice Mycloud CRITICAL 9.1
CVE-2024-30150

HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…

Mitigation only
Fix from $2,300 2025-02-25
Dryice Iautomate MEDIUM 6.0
CVE-2024-42207

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

Mitigation only
Fix from $1,600 2025-02-05
Dryice Myxalytics HIGH 7.5
CVE-2024-42181

HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti…

Mitigation only
Fix from $1,950 2025-01-12
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42180

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types…

Mitigation only
Fix from $2,300 2025-01-12
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42175

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. T…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42172

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics MEDIUM 6.4
CVE-2024-42171

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…

Mitigation only
Fix from $1,600 2025-01-11
Dryice Myxalytics MEDIUM 6.8
CVE-2024-42170

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…

Mitigation only
Fix from $1,600 2025-01-11
Dryice Myxalytics CRITICAL 9.4
CVE-2024-42168

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics HIGH 8.1
CVE-2024-42169

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user…

Mitigation only
Fix from $1,950 2025-01-11
Bigfix Compliance MEDIUM 5.4
CVE-2024-30140

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p…

Mitigation only
Fix from $1,600 2024-11-07
Connections MEDIUM 5.7
CVE-2024-30118

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…

Mitigation only
Fix from $1,600 2024-10-09
Domino HIGH 7.5
CVE-2024-23562

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi…

No fix yet
Fix from $1,950 2024-07-08
Dryice Aex HIGH 7.5
CVE-2024-30135

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

Mitigation only
Fix from $1,950 2024-06-28
Dryice Aex CRITICAL 9.8
CVE-2024-30110

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into…

Mitigation only
Fix from $2,300 2024-06-28
Dryice Aex HIGH 7.5
CVE-2024-30111

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted …

Mitigation only
Fix from $1,950 2024-06-28
Dryice Aex MEDIUM 6.1
CVE-2024-30109

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layer…

Mitigation only
Fix from $1,600 2024-06-28
Connections MEDIUM 5.4
CVE-2024-30112

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Mitigation only
Fix from $1,600 2024-06-25
Domino MEDIUM 5.4
CVE-2023-37539

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in th…

Mitigation only
Fix from $1,600 2024-06-06
Connections MEDIUM 6.5
CVE-2024-30107

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

Mitigation only
Fix from $1,600 2024-04-18
Dryice Myxalytics CRITICAL 9.8
CVE-2023-50347

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL querie…

Mitigation only
Fix from $2,300 2024-04-10
Connections MEDIUM 6.5
CVE-2023-28018

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacke…

Mitigation only
Fix from $1,600 2024-02-12
Sametime Chat And Meetings MEDIUM 6.1
CVE-2023-45698

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to pr…

Mitigation only
Fix from $1,600 2024-02-10
Dryice Myxalytics MEDIUM 6.5
CVE-2023-50343

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics MEDIUM 5.4
CVE-2023-50344

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics HIGH 7.5
CVE-2023-50341

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl…

Mitigation only
Fix from $1,950 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45722

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is …

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45723

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate …

Mitigation only
Fix from $2,300 2024-01-03