Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2024-42176 HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed f… Dryice Myxalytics Mitigation only Fix from $1,9502025-03-19 MEDIUM 5.7 CVE-2024-30154 HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit… Hcl Sx Mitigation only Fix from $1,6002025-03-03 CRITICAL 9.1 CVE-2024-30150 HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a… Dryice Mycloud Mitigation only Fix from $2,3002025-02-25 MEDIUM 6.0 CVE-2024-42207 HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session. Dryice Iautomate Mitigation only Fix from $1,6002025-02-05 HIGH 7.5 CVE-2024-42181 HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-12 CRITICAL 9.8 CVE-2024-42180 HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-12 CRITICAL 9.8 CVE-2024-42175 HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. T… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 CRITICAL 9.8 CVE-2024-42172 HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 MEDIUM 6.4 CVE-2024-42171 HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc… Dryice Myxalytics Mitigation only Fix from $1,6002025-01-11 MEDIUM 6.8 CVE-2024-42170 HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc… Dryice Myxalytics Mitigation only Fix from $1,6002025-01-11 CRITICAL 9.4 CVE-2024-42168 HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 HIGH 8.1 CVE-2024-42169 HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-11 MEDIUM 5.4 CVE-2024-30140 HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p… Bigfix Compliance Mitigation only Fix from $1,6002024-11-07 MEDIUM 5.7 CVE-2024-30118 HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl… Connections Mitigation only Fix from $1,6002024-10-09 HIGH 7.5 CVE-2024-23562 A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi… Domino No fix yet Fix from $1,9502024-07-08 HIGH 7.5 CVE-2024-30135 HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken. Dryice Aex Mitigation only Fix from $1,9502024-06-28 CRITICAL 9.8 CVE-2024-30110 HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into… Dryice Aex Mitigation only Fix from $2,3002024-06-28 HIGH 7.5 CVE-2024-30111 HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted … Dryice Aex Mitigation only Fix from $1,9502024-06-28 MEDIUM 6.1 CVE-2024-30109 HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layer… Dryice Aex Mitigation only Fix from $1,6002024-06-28 MEDIUM 5.4 CVE-2024-30112 HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow… Connections Mitigation only Fix from $1,6002024-06-25 MEDIUM 5.4 CVE-2023-37539 The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in th… Domino Mitigation only Fix from $1,6002024-06-06 MEDIUM 6.5 CVE-2024-30107 HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. Connections Mitigation only Fix from $1,6002024-04-18 CRITICAL 9.8 CVE-2023-50347 HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL querie… Dryice Myxalytics Mitigation only Fix from $2,3002024-04-10 MEDIUM 6.5 CVE-2023-28018 HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacke… Connections Mitigation only Fix from $1,6002024-02-12 MEDIUM 6.1 CVE-2023-45698 Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to pr… Sametime Chat And Meetings Mitigation only Fix from $1,6002024-02-10 MEDIUM 6.5 CVE-2023-50343 HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 5.4 CVE-2023-50344 HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 HIGH 7.5 CVE-2023-50341 HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl… Dryice Myxalytics Mitigation only Fix from $1,9502024-01-03 CRITICAL 9.8 CVE-2023-45722 HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-45723 HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03