Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Platform MEDIUM 5.3
CVE-2024-30117

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

Fix: 9.5.25 / 10.0.12+
Fix from $1,600 2024-10-14
Connections MEDIUM 5.7
CVE-2024-30118

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…

Mitigation only
Fix from $1,600 2024-10-09
Nomad Server On Domino HIGH 7.5
CVE-2024-30132

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information v…

Fix: 1.0.13+
Fix from $1,950 2024-10-01
Hcl Nomad HIGH 7.5
CVE-2024-23586

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain…

Fix: 1.0.13+
Fix from $1,950 2024-09-27
Traveler For Microsoft Outlook HIGH 7.5
CVE-2024-30134

The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.

Fix: 3.0.9+
Fix from $1,950 2024-09-26
Nomad Server On Domino MEDIUM 6.5
CVE-2024-30128

HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address.…

Fix: 1.0.13+
Fix from $1,600 2024-09-25
Nomad Server On Domino HIGH 7.5
CVE-2024-30130

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquir…

Fix: 1.0.12+
Fix from $1,950 2024-07-19
Bigfix Compliance MEDIUM 6.2
CVE-2024-30125

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

Fix: 2.0.11+
Fix from $1,600 2024-07-18
Domino HIGH 7.5
CVE-2024-23562

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi…

No fix yet
Fix from $1,950 2024-07-08
Nomad Server On Domino MEDIUM 6.5
CVE-2024-23588

HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerabili…

Fix: 1.0.12+
Fix from $1,600 2024-07-05
Dryice Aex HIGH 7.5
CVE-2024-30135

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

Mitigation only
Fix from $1,950 2024-06-28
Dryice Aex CRITICAL 9.8
CVE-2024-30110

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into…

Mitigation only
Fix from $2,300 2024-06-28
Dryice Aex HIGH 7.5
CVE-2024-30111

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted …

Mitigation only
Fix from $1,950 2024-06-28
Dryice Aex MEDIUM 6.1
CVE-2024-30109

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layer…

Mitigation only
Fix from $1,600 2024-06-28
Connections MEDIUM 5.4
CVE-2024-30112

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Mitigation only
Fix from $1,600 2024-06-25
Domino MEDIUM 5.4
CVE-2023-37539

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in th…

Mitigation only
Fix from $1,600 2024-06-06
Bigfix Platform HIGH 8.8
CVE-2024-23554

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

Fix: 9.5.25 / 10.0.12+
Fix from $1,950 2024-05-18
Bigfix Platform HIGH 7.5
CVE-2024-23556

SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

Fix: 9.5.25 / 10.0.12+
Fix from $1,950 2024-05-18
Bigfix Platform MEDIUM 6.7
CVE-2024-23583

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Fix: 9.5.25 / 10.0.12+
Fix from $1,600 2024-05-17
Connections MEDIUM 6.5
CVE-2024-30107

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

Mitigation only
Fix from $1,600 2024-04-18
Dryice Myxalytics CRITICAL 9.8
CVE-2023-50347

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL querie…

Mitigation only
Fix from $2,300 2024-04-10
Bigfix Platform HIGH 7.2
CVE-2023-45705

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

Fix: 10.0.11 / 11.0.2+
Fix from $1,950 2024-03-28
Domino MEDIUM 5.9
CVE-2023-37495

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino…

Fix: 14.0+
Fix from $1,600 2024-02-29
Bigfix Platform MEDIUM 5.4
CVE-2023-37529

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious ja…

Fix: 9.5.24 / 10.0.11+
Fix from $1,600 2024-02-29
Bigfix Platform MEDIUM 5.4
CVE-2023-37530

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious ja…

Fix: 9.5.24 / 10.0.11+
Fix from $1,600 2024-02-29
Connections MEDIUM 6.5
CVE-2023-28018

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacke…

Mitigation only
Fix from $1,600 2024-02-12
Sametime Chat And Meetings MEDIUM 6.1
CVE-2023-45698

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to pr…

Mitigation only
Fix from $1,600 2024-02-10
Sametime HIGH 7.5
CVE-2023-45696

Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be sto…

Fix: 12.0.2+
Fix from $1,950 2024-02-10
Sametime HIGH 7.5
CVE-2023-45718

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web …

Fix: 12.0.2+
Fix from $1,950 2024-02-09
Sametime HIGH 8.8
CVE-2023-50349

Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to…

Fix: 12.0.2+
Fix from $1,950 2024-02-09