Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Platform HIGH 7.8
CVE-2022-38659

In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

Fix: after 10.0.7
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44750

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Notes HIGH 7.8
CVE-2022-44751

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…

Mitigation only
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44752

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthentica…

Mitigation only
Fix from $1,950 2022-12-19
Bigfix Platform MEDIUM 6.5
CVE-2022-42453

There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in u…

Fix: 9.5.21 / 10.0.8+
Fix from $1,600 2022-12-19
Hcl Digital Experience MEDIUM 6.1
CVE-2022-38662

 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

Mitigation only
Fix from $1,600 2022-12-19
Digital Experience MEDIUM 5.4
CVE-2022-38653

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

Mitigation only
Fix from $1,600 2022-12-19
Sametime MEDIUM 6.5
CVE-2022-42446

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire…

Mitigation only
Fix from $1,600 2022-12-12
Domino MEDIUM 5.5
CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directo…

Mitigation only
Fix from $1,600 2022-11-04
Domino HIGH 8.8
CVE-2022-38660

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnera…

Fix: 9.0.1+
Fix from $1,950 2022-11-04
Verse HIGH 7.5
CVE-2020-4099

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An atta…

Fix: 12.0.15+
Fix from $1,950 2022-11-01
Hcl Launch Container Image HIGH 7.5
CVE-2021-27784

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools t…

Fix: 7.1.0.1+
Fix from $1,950 2022-10-31
Hcl Digital Experience MEDIUM 5.4
CVE-2021-27774

User input included in error response, which could be used in a phishing attack.

Mitigation only
Fix from $1,600 2022-09-22
Versionvault Express HIGH 7.5
CVE-2022-27563

An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

Mitigation only
Fix from $1,950 2022-08-30
Versionvault Express MEDIUM 6.5
CVE-2022-27560

HCL VersionVault Express exposes administrator credentials.

Mitigation only
Fix from $1,600 2022-08-30
Domino HIGH 7.5
CVE-2022-27558

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which…

Mitigation only
Fix from $1,950 2022-08-29
Hcl Inotes HIGH 7.4
CVE-2022-27547

HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sen…

No fix yet
Fix from $1,950 2022-08-29
Hcl Inotes MEDIUM 6.1
CVE-2022-27546

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with …

Mitigation only
Fix from $1,600 2022-08-29
Bigfix Platform MEDIUM 6.5
CVE-2022-27544

BigFix Web Reports authorized users may see SMTP credentials in clear text.

Fix: after 10.0.6
Fix from $1,600 2022-07-19
Bigfix Platform MEDIUM 5.4
CVE-2022-27545

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

Fix: after 10.0.6
Fix from $1,600 2022-07-19
Onetest Server CRITICAL 9.8
CVE-2021-27786

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that…

No fix yet
Fix from $2,300 2022-06-09
Bigfix Mobile MEDIUM 5.3
CVE-2021-27780

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

Fix: 2.1+
Fix from $1,600 2022-05-27
Bigfix Mobile MEDIUM 6.5
CVE-2021-27783

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

Mitigation only
Fix from $1,600 2022-05-25
Versionvault Express CRITICAL 9.1
CVE-2021-27779

VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

No fix yet
Fix from $2,300 2022-05-25
Domino HIGH 7.8
CVE-2020-4107

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this …

Mitigation only
Fix from $1,950 2022-05-19
Unica HIGH 7.5
CVE-2021-27777

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validatio…

Fix: 12.1.1+
Fix from $1,950 2022-05-12
Sametime HIGH 8.8
CVE-2021-27770

The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We ass…

Mitigation only
Fix from $1,950 2022-05-12
Sametime HIGH 7.6
CVE-2021-27771

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m…

Mitigation only
Fix from $1,950 2022-05-12
Sametime MEDIUM 6.5
CVE-2021-27772

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conv…

Mitigation only
Fix from $1,600 2022-05-12
Verse MEDIUM 5.9
CVE-2021-27768

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was ab…

Fix: 12.0.9+
Fix from $1,600 2022-05-12