Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dryice Myxalytics CRITICAL 9.8
CVE-2023-45724

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file with…

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.1
CVE-2023-50351

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or i…

No fix yet
Fix from $2,300 2024-01-03
Dryice Myxalytics HIGH 7.5
CVE-2023-50350

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt se…

Mitigation only
Fix from $1,950 2024-01-03
Dryice Myxalytics MEDIUM 5.3
CVE-2023-50348

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an at…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics MEDIUM 6.1
CVE-2023-50345

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l…

Mitigation only
Fix from $1,600 2024-01-03
Connections MEDIUM 6.5
CVE-2023-28022

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…

Mitigation only
Fix from $1,600 2023-12-15
Connections MEDIUM 6.1
CVE-2023-37533

HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in…

Mitigation only
Fix from $1,600 2023-11-09
Domino MEDIUM 5.3
CVE-2023-28010

In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.

Mitigation only
Fix from $1,600 2023-09-08
Dryice Iautomate HIGH 7.1
CVE-2023-23347

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and inte…

No fix yet
Fix from $1,950 2023-08-09
Dryice Mycloud HIGH 7.1
CVE-2023-23346

HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integr…

Mitigation only
Fix from $1,950 2023-08-09
Bigfix Mobile HIGH 8.8
CVE-2023-28012

HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

Mitigation only
Fix from $1,950 2023-07-27
Bigfix Mobile MEDIUM 5.4
CVE-2023-28014

HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

Mitigation only
Fix from $1,600 2023-07-27
Bigfix Webui HIGH 7.5
CVE-2023-28021

The BigFix WebUI uses weak cipher suites.

No fix yet
Fix from $1,950 2023-07-18
Bigfix Webui MEDIUM 6.1
CVE-2023-28020

 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response…

Mitigation only
Fix from $1,600 2023-07-18
Bigfix Webui Insights MEDIUM 6.5
CVE-2023-23344

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

Mitigation only
Fix from $1,600 2023-06-23
Workload Automation HIGH 8.1
CVE-2023-28008

HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2023-04-26
Workload Automation HIGH 8.1
CVE-2023-28009

HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…

Mitigation only
Fix from $1,950 2023-04-26
Bigfix Mobile HIGH 7.5
CVE-2021-27782

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attemp…

Mitigation only
Fix from $1,950 2023-01-20
Bigfix Webui MEDIUM 5.8
CVE-2022-38655

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from…

Mitigation only
Fix from $1,600 2022-12-21
Notes HIGH 7.8
CVE-2022-44753

HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44754

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Notes HIGH 7.8
CVE-2022-44755

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…

Mitigation only
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44750

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Notes HIGH 7.8
CVE-2022-44751

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…

Mitigation only
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44752

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthentica…

Mitigation only
Fix from $1,950 2022-12-19
Hcl Digital Experience MEDIUM 6.1
CVE-2022-38662

 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

Mitigation only
Fix from $1,600 2022-12-19
Digital Experience MEDIUM 5.4
CVE-2022-38653

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

Mitigation only
Fix from $1,600 2022-12-19
Sametime MEDIUM 6.5
CVE-2022-42446

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire…

Mitigation only
Fix from $1,600 2022-12-12
Domino MEDIUM 5.5
CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directo…

Mitigation only
Fix from $1,600 2022-11-04
Hcl Digital Experience MEDIUM 5.4
CVE-2021-27774

User input included in error response, which could be used in a phishing attack.

Mitigation only
Fix from $1,600 2022-09-22