Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.0
CVE-2024-42176
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed f…
Dryice Myxalytics
Mitigation only
MEDIUM 5.7
CVE-2024-30154
HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit…
Hcl Sx
Mitigation only
CRITICAL 9.1
CVE-2024-30150
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…
Dryice Mycloud
Mitigation only
MEDIUM 6.0
CVE-2024-42207
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.
Dryice Iautomate
Mitigation only
HIGH 7.5
CVE-2024-42181
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti…
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2024-42180
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types…
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2024-42175
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. T…
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2024-42172
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…
Dryice Myxalytics
Mitigation only
MEDIUM 6.4
CVE-2024-42171
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…
Dryice Myxalytics
Mitigation only
MEDIUM 6.8
CVE-2024-42170
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…
Dryice Myxalytics
Mitigation only
CRITICAL 9.4
CVE-2024-42168
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an…
Dryice Myxalytics
Mitigation only
HIGH 8.1
CVE-2024-42169
HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user…
Dryice Myxalytics
Mitigation only
MEDIUM 5.4
CVE-2024-30140
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p…
Bigfix Compliance
Mitigation only
MEDIUM 5.7
CVE-2024-30118
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…
Connections
Mitigation only
HIGH 7.5
CVE-2024-23562
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi…
Domino
No fix yet
HIGH 7.5
CVE-2024-30135
HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.
Dryice Aex
Mitigation only
CRITICAL 9.8
CVE-2024-30110
HCL DRYiCE
AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into…
Dryice Aex
Mitigation only
HIGH 7.5
CVE-2024-30111
HCL DRYiCE AEX product is impacted by Missing
Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted
…
Dryice Aex
Mitigation only
MEDIUM 6.1
CVE-2024-30109
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layer…
Dryice Aex
Mitigation only
MEDIUM 5.4
CVE-2024-30112
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…
Connections
Mitigation only
MEDIUM 5.4
CVE-2023-37539
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in th…
Domino
Mitigation only
MEDIUM 6.5
CVE-2024-30107
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
Connections
Mitigation only
CRITICAL 9.8
CVE-2023-50347
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL querie…
Dryice Myxalytics
Mitigation only
MEDIUM 6.5
CVE-2023-28018
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacke…
Connections
Mitigation only
MEDIUM 6.1
CVE-2023-45698
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to pr…
Sametime Chat And Meetings
Mitigation only
MEDIUM 6.5
CVE-2023-50343
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm…
Dryice Myxalytics
Mitigation only
MEDIUM 5.4
CVE-2023-50344
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert…
Dryice Myxalytics
Mitigation only
HIGH 7.5
CVE-2023-50341
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl…
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2023-45722
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is …
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2023-45723
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate …
Dryice Myxalytics
Mitigation only