Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hcl Leap MEDIUM 5.4
CVE-2022-44759

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

Fix: 9.3.1+
Fix from $1,600 2025-04-24
Hcl Leap MEDIUM 6.1
CVE-2024-30147

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

Fix: 9.3.8+
Fix from $1,600 2025-04-24
Hcl Leap MEDIUM 5.4
CVE-2024-30114

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

Fix: 9.3.6+
Fix from $1,600 2025-04-24
Hcl Leap MEDIUM 5.4
CVE-2024-30113

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Fix: 9.3.6+
Fix from $1,600 2025-04-24
Hcl Leap MEDIUM 5.3
CVE-2023-45720

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Fix: 9.3.5+
Fix from $1,600 2025-04-24
Hcl Leap MEDIUM 6.1
CVE-2023-37534

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

Fix: 9.3.4+
Fix from $1,600 2025-04-24
Dryice Myxalytics HIGH 7.5
CVE-2024-42178

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con…

Mitigation only
Fix from $1,950 2025-04-17
Dryice Myxalytics MEDIUM 6.4
CVE-2024-42177

HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to i…

Mitigation only
Fix from $1,600 2025-04-17
Bigfix Platform HIGH 8.1
CVE-2024-42193

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents…

Fix: 10.0.13 / 11.0.4+
Fix from $1,950 2025-04-15
Bigfix Platform MEDIUM 5.4
CVE-2024-42200

HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

Fix: 10.0.13 / 11.0.4+
Fix from $1,600 2025-04-15
Bigfix Platform MEDIUM 6.5
CVE-2024-42189

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

Fix: 10.0.13 / 11.0.4+
Fix from $1,600 2025-04-15
Dryice Myxalytics HIGH 8.0
CVE-2024-42176

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed f…

Mitigation only
Fix from $1,950 2025-03-19
Hcl Sx MEDIUM 5.7
CVE-2024-30154

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit…

Mitigation only
Fix from $1,600 2025-03-03
Dryice Mycloud CRITICAL 9.1
CVE-2024-30150

HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…

Mitigation only
Fix from $2,300 2025-02-25
Dryice Iautomate MEDIUM 6.0
CVE-2024-42207

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

Mitigation only
Fix from $1,600 2025-02-05
Devops Velocity HIGH 7.5
CVE-2024-22347

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an att…

Fix: after 4.0.15
Fix from $1,950 2025-01-20
Devops Velocity HIGH 7.5
CVE-2024-22348

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to…

Fix: after 4.0.15
Fix from $1,950 2025-01-20
Dryice Myxalytics HIGH 7.5
CVE-2024-42181

HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti…

Mitigation only
Fix from $1,950 2025-01-12
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42180

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types…

Mitigation only
Fix from $2,300 2025-01-12
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42175

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. T…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42172

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics MEDIUM 6.4
CVE-2024-42171

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…

Mitigation only
Fix from $1,600 2025-01-11
Dryice Myxalytics MEDIUM 6.8
CVE-2024-42170

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc…

Mitigation only
Fix from $1,600 2025-01-11
Dryice Myxalytics CRITICAL 9.4
CVE-2024-42168

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an…

Mitigation only
Fix from $2,300 2025-01-11
Dryice Myxalytics HIGH 8.1
CVE-2024-42169

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user…

Mitigation only
Fix from $1,950 2025-01-11
Traveler For Microsoft Outlook MEDIUM 5.3
CVE-2024-30133

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control f…

Fix: 3.0.11+
Fix from $1,600 2024-11-12
Bigfix Compliance MEDIUM 5.4
CVE-2024-30140

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p…

Mitigation only
Fix from $1,600 2024-11-07
Appscan Source MEDIUM 6.5
CVE-2024-30149

HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Fix: 10.7.0+
Fix from $1,600 2024-10-31
Sametime MEDIUM 5.3
CVE-2023-50355

HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focuse…

Fix: 12.0.2+
Fix from $1,600 2024-10-23
Sametime MEDIUM 5.3
CVE-2024-30122

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service respons…

Fix: 12.0.2+
Fix from $1,600 2024-10-23