Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-45724
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file with…
Dryice Myxalytics
Mitigation only
CRITICAL 9.1
CVE-2023-50351
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or i…
Dryice Myxalytics
No fix yet
HIGH 7.5
CVE-2023-50350
HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt se…
Dryice Myxalytics
Mitigation only
MEDIUM 5.3
CVE-2023-50348
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an at…
Dryice Myxalytics
Mitigation only
MEDIUM 6.1
CVE-2023-50345
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l…
Dryice Myxalytics
Mitigation only
MEDIUM 6.5
CVE-2023-28022
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…
Connections
Mitigation only
MEDIUM 6.1
CVE-2023-37533
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in…
Connections
Mitigation only
MEDIUM 5.3
CVE-2023-28010
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
Domino
Mitigation only
HIGH 7.1
CVE-2023-23347
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and inte…
Dryice Iautomate
No fix yet
HIGH 7.1
CVE-2023-23346
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integr…
Dryice Mycloud
Mitigation only
HIGH 8.8
CVE-2023-28012
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
Bigfix Mobile
Mitigation only
MEDIUM 5.4
CVE-2023-28014
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
Bigfix Mobile
Mitigation only
HIGH 7.5
CVE-2023-28021
The BigFix WebUI uses weak cipher suites.
Bigfix Webui
No fix yet
MEDIUM 6.1
CVE-2023-28020
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response…
Bigfix Webui
Mitigation only
MEDIUM 6.5
CVE-2023-23344
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
Bigfix Webui Insights
Mitigation only
HIGH 8.1
CVE-2023-28008
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…
Workload Automation
Mitigation only
HIGH 8.1
CVE-2023-28009
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
Workload Automation
Mitigation only
HIGH 7.5
CVE-2021-27782
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced.
User should be locked out for multiple invalid attemp…
Bigfix Mobile
Mitigation only
MEDIUM 5.8
CVE-2022-38655
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from…
Bigfix Webui
Mitigation only
HIGH 7.8
CVE-2022-44753
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…
Notes
Mitigation only
HIGH 7.8
CVE-2022-44754
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…
Domino
Mitigation only
HIGH 7.8
CVE-2022-44755
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…
Notes
Mitigation only
HIGH 7.8
CVE-2022-44750
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…
Domino
Mitigation only
HIGH 7.8
CVE-2022-44751
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…
Notes
Mitigation only
HIGH 7.8
CVE-2022-44752
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthentica…
Domino
Mitigation only
MEDIUM 6.1
CVE-2022-38662
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
Hcl Digital Experience
Mitigation only
MEDIUM 5.4
CVE-2022-38653
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
Digital Experience
Mitigation only
MEDIUM 6.5
CVE-2022-42446
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire…
Sametime
Mitigation only
MEDIUM 5.5
CVE-2022-38654
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directo…
Domino
Mitigation only
MEDIUM 5.4
CVE-2021-27774
User input included in error response, which could be used in a phishing attack.
Hcl Digital Experience
Mitigation only