Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Versionvault Express HIGH 7.5
CVE-2022-27563

An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

Mitigation only
Fix from $1,950 2022-08-30
Versionvault Express MEDIUM 6.5
CVE-2022-27560

HCL VersionVault Express exposes administrator credentials.

Mitigation only
Fix from $1,600 2022-08-30
Domino HIGH 7.5
CVE-2022-27558

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which…

Mitigation only
Fix from $1,950 2022-08-29
Hcl Inotes HIGH 7.4
CVE-2022-27547

HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sen…

No fix yet
Fix from $1,950 2022-08-29
Hcl Inotes MEDIUM 6.1
CVE-2022-27546

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with …

Mitigation only
Fix from $1,600 2022-08-29
Onetest Server CRITICAL 9.8
CVE-2021-27786

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that…

No fix yet
Fix from $2,300 2022-06-09
Bigfix Mobile MEDIUM 6.5
CVE-2021-27783

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

Mitigation only
Fix from $1,600 2022-05-25
Versionvault Express CRITICAL 9.1
CVE-2021-27779

VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

No fix yet
Fix from $2,300 2022-05-25
Domino HIGH 7.8
CVE-2020-4107

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this …

Mitigation only
Fix from $1,950 2022-05-19
Sametime HIGH 8.8
CVE-2021-27770

The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We ass…

Mitigation only
Fix from $1,950 2022-05-12
Sametime HIGH 7.6
CVE-2021-27771

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m…

Mitigation only
Fix from $1,950 2022-05-12
Sametime MEDIUM 6.5
CVE-2021-27772

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conv…

Mitigation only
Fix from $1,600 2022-05-12
Sametime MEDIUM 5.3
CVE-2021-27769

Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may n…

No fix yet
Fix from $1,600 2022-05-12
Bigfix Webui MEDIUM 6.5
CVE-2021-27764

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

Mitigation only
Fix from $1,600 2022-05-06
Hcl Inotes MEDIUM 5.5
CVE-2021-27760

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote C…

Mitigation only
Fix from $1,600 2022-05-06
Digital Experience MEDIUM 6.1
CVE-2020-4081

In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).

Mitigation only
Fix from $1,600 2021-02-02
Digital Experience HIGH 7.5
CVE-2020-14255

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af…

Mitigation only
Fix from $1,950 2021-02-02
Domino HIGH 7.5
CVE-2020-14273

HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at…

No fix yet
Fix from $1,950 2020-12-28
Notes HIGH 8.8
CVE-2020-14232

A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buff…

Mitigation only
Fix from $1,950 2020-12-18
Hcl Digital Experience MEDIUM 6.1
CVE-2020-14222

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS,…

Mitigation only
Fix from $1,600 2020-11-05
Bigfix Webui MEDIUM 5.4
CVE-2020-4104

HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious scr…

Mitigation only
Fix from $1,600 2020-07-17
Notes MEDIUM 6.5
CVE-2020-4089

HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in fil…

Mitigation only
Fix from $1,600 2020-06-26
Hcl Digital Experience CRITICAL 9.8
CVE-2020-4101

"HCL Digital Experience is susceptible to Server Side Request Forgery."

Mitigation only
Fix from $2,300 2020-06-11
Hcl Nomad MEDIUM 5.3
CVE-2020-4092

"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently…

Mitigation only
Fix from $1,600 2020-05-06
Connections MEDIUM 6.5
CVE-2020-4085

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

Mitigation only
Fix from $1,600 2020-04-22
Self Service Application HIGH 8.4
CVE-2019-4301

BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTM…

Mitigation only
Fix from $1,950 2020-02-28
Legacy Ivr Firmware HIGH 8.1
CVE-2018-11518

A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio sign…

Mitigation only
Fix from $1,950 2018-05-30