Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2021-27769
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may n…
Sametime
No fix yet
HIGH 7.8
CVE-2021-27765
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to…
Bigfix Platform
after 10.0.5
HIGH 7.8
CVE-2021-27766
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to per…
Bigfix Platform
after 10.0.5
HIGH 7.8
CVE-2021-27767
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to pe…
Bigfix Platform
after 10.0.5
CRITICAL 9.8
CVE-2021-27762
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
Bigfix Platform
9.5.19 / 10.0.6+
HIGH 7.5
CVE-2021-27761
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
Bigfix Platform
9.5.19 / 10.0.6+
MEDIUM 6.5
CVE-2021-27758
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s…
Bigfix Inventory
10.0.7.0+
MEDIUM 6.5
CVE-2021-27759
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent…
Bigfix Inventory
10.0.7.0+
MEDIUM 6.5
CVE-2021-27764
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
Bigfix Webui
Mitigation only
MEDIUM 5.5
CVE-2021-27760
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote C…
Hcl Inotes
Mitigation only
HIGH 7.5
CVE-2021-27756
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passive…
Bigfix Compliance
2.0.6+
HIGH 7.5
CVE-2021-27757
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another con…
Bigfix Insights
10.0.8.0+
MEDIUM 5.5
CVE-2021-27753
"Sametime Android PathTraversal Vulnerability"
Hcl Sametime
11.6.5+
MEDIUM 5.5
CVE-2021-27755
"Sametime Android potential path traversal vulnerability when using File class"
Hcl Sametime
11.6.5+
MEDIUM 6.1
CVE-2020-4081
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
Digital Experience
Mitigation only
HIGH 7.5
CVE-2020-14255
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af…
Digital Experience
Mitigation only
HIGH 7.5
CVE-2020-14273
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at…
Domino
No fix yet
MEDIUM 5.3
CVE-2020-14270
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthen…
Domino
after 10.0.0
MEDIUM 6.5
CVE-2020-14225
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could u…
Hcl Inotes
9.0.1+
CRITICAL 9.8
CVE-2020-14224
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a …
Notes
Patch available
MEDIUM 6.1
CVE-2020-14271
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauth…
Hcl Inotes
10.0.1 / 11.0.1+
MEDIUM 6.1
CVE-2020-4080
HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthentic…
Domino
Patch available
HIGH 8.8
CVE-2020-14232
A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buff…
Notes
Mitigation only
HIGH 7.5
CVE-2020-14254
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can pass…
Bigfix Platform
after 10.0.2
MEDIUM 5.3
CVE-2020-14248
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http…
Bigfix Platform
after 10.0.2
CRITICAL 9.8
CVE-2020-14244
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker r…
Domino
10.0.1+
CRITICAL 9.8
CVE-2020-14268
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker re…
Notes
9.0.1 / 10.0.1+
CRITICAL 9.8
CVE-2020-14260
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an at…
Domino
after 11.0.1
MEDIUM 6.7
CVE-2020-4102
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an att…
Notes
after 9.0.1
MEDIUM 5.3
CVE-2020-4128
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability …
Domino
after 11.0.1