Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Platform MEDIUM 6.1
CVE-2023-37528

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application…

Fix: 9.5.24 / 10.0.11+
Fix from $1,600 2024-02-03
Bigfix Platform MEDIUM 5.4
CVE-2024-23553

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

Fix: 9.5.24 / 10.0.11+
Fix from $1,600 2024-02-02
Bigfix Platform MEDIUM 6.1
CVE-2023-37527

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute ma…

Fix: 9.5.24 / 10.0.11+
Fix from $1,600 2024-02-02
Bigfix Servicenow Data Flow HIGH 8.8
CVE-2023-37518

HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the …

Fix: 1.3+
Fix from $1,950 2024-01-30
Dryice Myxalytics MEDIUM 6.5
CVE-2023-50343

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics MEDIUM 5.4
CVE-2023-50344

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics HIGH 7.5
CVE-2023-50341

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl…

Mitigation only
Fix from $1,950 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45722

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is …

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45723

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate …

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45724

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file with…

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.1
CVE-2023-50351

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or i…

No fix yet
Fix from $2,300 2024-01-03
Dryice Myxalytics HIGH 7.5
CVE-2023-50350

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt se…

Mitigation only
Fix from $1,950 2024-01-03
Dryice Myxalytics MEDIUM 5.3
CVE-2023-50348

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an at…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics MEDIUM 6.1
CVE-2023-50345

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l…

Mitigation only
Fix from $1,600 2024-01-03
Bigfix Platform MEDIUM 6.1
CVE-2023-37520

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltrati…

Fix: 9.5.23 / 10.0.10+
Fix from $1,600 2023-12-21
Bigfix Platform MEDIUM 6.1
CVE-2023-37519

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigF…

Fix: 9.5.23 / 10.0.10+
Fix from $1,600 2023-12-21
Connections MEDIUM 6.5
CVE-2023-28022

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…

Mitigation only
Fix from $1,600 2023-12-15
Connections MEDIUM 5.4
CVE-2023-28017

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Patch available
Fix from $1,600 2023-12-07
Connections MEDIUM 6.1
CVE-2023-37533

HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in…

Mitigation only
Fix from $1,600 2023-11-09
Hcl Compass CRITICAL 9.8
CVE-2023-37503

HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

Fix: 2.2.3+
Fix from $2,300 2023-10-19
Hcl Compass MEDIUM 6.5
CVE-2023-37504

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionalit…

Fix: 2.2.3+
Fix from $1,600 2023-10-19
Hcl Compass HIGH 8.8
CVE-2023-37502

HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server …

Fix: 2.2.3+
Fix from $1,950 2023-10-18
Appscan Presence HIGH 7.8
CVE-2023-37537

An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attac…

Fix: after 2.1.37
Fix from $1,950 2023-10-17
Digital Experience MEDIUM 6.1
CVE-2023-37538

HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker m…

Patch available
Fix from $1,600 2023-10-11
Bigfix Insights For Vulnerability Remediation HIGH 8.2
CVE-2022-44757

BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to se…

Fix: 2.0.3+
Fix from $1,950 2023-10-11
Bigfix Insights For Vulnerability Remediation MEDIUM 5.3
CVE-2022-44758

BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not e…

Fix: 2.0.3+
Fix from $1,600 2023-10-11
Domino MEDIUM 5.3
CVE-2023-28010

In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.

Mitigation only
Fix from $1,600 2023-09-08
Traveler Companion MEDIUM 5.5
CVE-2023-37512

When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive infor…

Fix: 12.0.6+
Fix from $1,600 2023-08-11
Traveler To Do MEDIUM 5.5
CVE-2023-37513

When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive infor…

Fix: 12.0.6+
Fix from $1,600 2023-08-11
Hcl Nomad HIGH 7.1
CVE-2023-23342

If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 

Fix: 1.0.7+
Fix from $1,950 2023-08-10