Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sametime MEDIUM 5.3
CVE-2021-27769

Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may n…

No fix yet
Fix from $1,600 2022-05-12
Bigfix Platform HIGH 7.8
CVE-2021-27765

The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to…

Fix: after 10.0.5
Fix from $1,950 2022-05-06
Bigfix Platform HIGH 7.8
CVE-2021-27766

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to per…

Fix: after 10.0.5
Fix from $1,950 2022-05-06
Bigfix Platform HIGH 7.8
CVE-2021-27767

The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to pe…

Fix: after 10.0.5
Fix from $1,950 2022-05-06
Bigfix Platform CRITICAL 9.8
CVE-2021-27762

Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

Fix: 9.5.19 / 10.0.6+
Fix from $2,300 2022-05-06
Bigfix Platform HIGH 7.5
CVE-2021-27761

Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

Fix: 9.5.19 / 10.0.6+
Fix from $1,950 2022-05-06
Bigfix Inventory MEDIUM 6.5
CVE-2021-27758

There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s…

Fix: 10.0.7.0+
Fix from $1,600 2022-05-06
Bigfix Inventory MEDIUM 6.5
CVE-2021-27759

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent…

Fix: 10.0.7.0+
Fix from $1,600 2022-05-06
Bigfix Webui MEDIUM 6.5
CVE-2021-27764

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

Mitigation only
Fix from $1,600 2022-05-06
Hcl Inotes MEDIUM 5.5
CVE-2021-27760

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote C…

Mitigation only
Fix from $1,600 2022-05-06
Bigfix Compliance HIGH 7.5
CVE-2021-27756

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passive…

Fix: 2.0.6+
Fix from $1,950 2022-03-04
Bigfix Insights HIGH 7.5
CVE-2021-27757

" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another con…

Fix: 10.0.8.0+
Fix from $1,950 2022-03-04
Hcl Sametime MEDIUM 5.5
CVE-2021-27753

"Sametime Android PathTraversal Vulnerability"

Fix: 11.6.5+
Fix from $1,600 2022-02-21
Hcl Sametime MEDIUM 5.5
CVE-2021-27755

"Sametime Android potential path traversal vulnerability when using File class"

Fix: 11.6.5+
Fix from $1,600 2022-02-21
Digital Experience MEDIUM 6.1
CVE-2020-4081

In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).

Mitigation only
Fix from $1,600 2021-02-02
Digital Experience HIGH 7.5
CVE-2020-14255

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af…

Mitigation only
Fix from $1,950 2021-02-02
Domino HIGH 7.5
CVE-2020-14273

HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at…

No fix yet
Fix from $1,950 2020-12-28
Domino MEDIUM 5.3
CVE-2020-14270

HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthen…

Fix: after 10.0.0
Fix from $1,600 2020-12-22
Hcl Inotes MEDIUM 6.5
CVE-2020-14225

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could u…

Fix: 9.0.1+
Fix from $1,600 2020-12-21
Notes CRITICAL 9.8
CVE-2020-14224

A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a …

Patch available
Fix from $2,300 2020-12-18
Hcl Inotes MEDIUM 6.1
CVE-2020-14271

HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauth…

Fix: 10.0.1 / 11.0.1+
Fix from $1,600 2020-12-18
Domino MEDIUM 6.1
CVE-2020-4080

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthentic…

Patch available
Fix from $1,600 2020-12-18
Notes HIGH 8.8
CVE-2020-14232

A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buff…

Mitigation only
Fix from $1,950 2020-12-18
Bigfix Platform HIGH 7.5
CVE-2020-14254

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can pass…

Fix: after 10.0.2
Fix from $1,950 2020-12-16
Bigfix Platform MEDIUM 5.3
CVE-2020-14248

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http…

Fix: after 10.0.2
Fix from $1,600 2020-12-16
Domino CRITICAL 9.8
CVE-2020-14244

A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker r…

Fix: 10.0.1+
Fix from $2,300 2020-12-14
Notes CRITICAL 9.8
CVE-2020-14268

A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker re…

Fix: 9.0.1 / 10.0.1+
Fix from $2,300 2020-12-14
Domino CRITICAL 9.8
CVE-2020-14260

HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an at…

Fix: after 11.0.1
Fix from $2,300 2020-12-02
Notes MEDIUM 6.7
CVE-2020-4102

HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an att…

Fix: after 9.0.1
Fix from $1,600 2020-12-02
Domino MEDIUM 5.3
CVE-2020-4128

HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability …

Fix: after 11.0.1
Fix from $1,600 2020-12-01