Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-44759 Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. Hcl Leap 9.3.1+ Fix from $1,6002025-04-24 MEDIUM 6.1 CVE-2024-30147 Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. Hcl Leap 9.3.8+ Fix from $1,6002025-04-24 MEDIUM 5.4 CVE-2024-30114 Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. Hcl Leap 9.3.6+ Fix from $1,6002025-04-24 MEDIUM 5.4 CVE-2024-30113 Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. Hcl Leap 9.3.6+ Fix from $1,6002025-04-24 MEDIUM 5.3 CVE-2023-45720 Insufficient default configuration in HCL Leap allows anonymous access to directory information. Hcl Leap 9.3.5+ Fix from $1,6002025-04-24 MEDIUM 6.1 CVE-2023-37534 Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. Hcl Leap 9.3.4+ Fix from $1,6002025-04-24 HIGH 7.5 CVE-2024-42178 HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con… Dryice Myxalytics Mitigation only Fix from $1,9502025-04-17 MEDIUM 6.4 CVE-2024-42177 HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to i… Dryice Myxalytics Mitigation only Fix from $1,6002025-04-17 HIGH 8.1 CVE-2024-42193 HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents… Bigfix Platform 10.0.13 / 11.0.4+ Fix from $1,9502025-04-15 MEDIUM 5.4 CVE-2024-42200 HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input. Bigfix Platform 10.0.13 / 11.0.4+ Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2024-42189 HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter. Bigfix Platform 10.0.13 / 11.0.4+ Fix from $1,6002025-04-15 HIGH 8.0 CVE-2024-42176 HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed f… Dryice Myxalytics Mitigation only Fix from $1,9502025-03-19 MEDIUM 5.7 CVE-2024-30154 HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit… Hcl Sx Mitigation only Fix from $1,6002025-03-03 CRITICAL 9.1 CVE-2024-30150 HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a… Dryice Mycloud Mitigation only Fix from $2,3002025-02-25 MEDIUM 6.0 CVE-2024-42207 HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session. Dryice Iautomate Mitigation only Fix from $1,6002025-02-05 HIGH 7.5 CVE-2024-22347 IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an att… Devops Velocity after 4.0.15 Fix from $1,9502025-01-20 HIGH 7.5 CVE-2024-22348 IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to… Devops Velocity after 4.0.15 Fix from $1,9502025-01-20 HIGH 7.5 CVE-2024-42181 HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-12 CRITICAL 9.8 CVE-2024-42180 HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-12 CRITICAL 9.8 CVE-2024-42175 HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. T… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 CRITICAL 9.8 CVE-2024-42172 HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 MEDIUM 6.4 CVE-2024-42171 HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc… Dryice Myxalytics Mitigation only Fix from $1,6002025-01-11 MEDIUM 6.8 CVE-2024-42170 HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to acc… Dryice Myxalytics Mitigation only Fix from $1,6002025-01-11 CRITICAL 9.4 CVE-2024-42168 HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, an… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 HIGH 8.1 CVE-2024-42169 HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-11 MEDIUM 5.3 CVE-2024-30133 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control f… Traveler For Microsoft Outlook 3.0.11+ Fix from $1,6002024-11-12 MEDIUM 5.4 CVE-2024-30140 HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can p… Bigfix Compliance Mitigation only Fix from $1,6002024-11-07 MEDIUM 6.5 CVE-2024-30149 HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. Appscan Source 10.7.0+ Fix from $1,6002024-10-31 MEDIUM 5.3 CVE-2023-50355 HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focuse… Sametime 12.0.2+ Fix from $1,6002024-10-23 MEDIUM 5.3 CVE-2024-30122 HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service respons… Sametime 12.0.2+ Fix from $1,6002024-10-23