Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-30117 A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances. Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,6002024-10-14 MEDIUM 5.7 CVE-2024-30118 HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl… Connections Mitigation only Fix from $1,6002024-10-09 HIGH 7.5 CVE-2024-30132 HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information v… Nomad Server On Domino 1.0.13+ Fix from $1,9502024-10-01 HIGH 7.5 CVE-2024-23586 HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain… Hcl Nomad 1.0.13+ Fix from $1,9502024-09-27 HIGH 7.5 CVE-2024-30134 The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. Traveler For Microsoft Outlook 3.0.9+ Fix from $1,9502024-09-26 MEDIUM 6.5 CVE-2024-30128 HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address.… Nomad Server On Domino 1.0.13+ Fix from $1,6002024-09-25 HIGH 7.5 CVE-2024-30130 HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquir… Nomad Server On Domino 1.0.12+ Fix from $1,9502024-07-19 MEDIUM 6.2 CVE-2024-30125 HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die. Bigfix Compliance 2.0.11+ Fix from $1,6002024-07-18 HIGH 7.5 CVE-2024-23562 A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi… Domino No fix yet Fix from $1,9502024-07-08 MEDIUM 6.5 CVE-2024-23588 HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerabili… Nomad Server On Domino 1.0.12+ Fix from $1,6002024-07-05 HIGH 7.5 CVE-2024-30135 HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken. Dryice Aex Mitigation only Fix from $1,9502024-06-28 CRITICAL 9.8 CVE-2024-30110 HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into… Dryice Aex Mitigation only Fix from $2,3002024-06-28 HIGH 7.5 CVE-2024-30111 HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted … Dryice Aex Mitigation only Fix from $1,9502024-06-28 MEDIUM 6.1 CVE-2024-30109 HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layer… Dryice Aex Mitigation only Fix from $1,6002024-06-28 MEDIUM 5.4 CVE-2024-30112 HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow… Connections Mitigation only Fix from $1,6002024-06-25 MEDIUM 5.4 CVE-2023-37539 The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in th… Domino Mitigation only Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-23554 Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,9502024-05-18 HIGH 7.5 CVE-2024-23556 SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability. Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,9502024-05-18 MEDIUM 6.7 CVE-2024-23583 An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems. Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,6002024-05-17 MEDIUM 6.5 CVE-2024-30107 HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. Connections Mitigation only Fix from $1,6002024-04-18 CRITICAL 9.8 CVE-2023-50347 HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL querie… Dryice Myxalytics Mitigation only Fix from $2,3002024-04-10 HIGH 7.2 CVE-2023-45705 An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options. Bigfix Platform 10.0.11 / 11.0.2+ Fix from $1,9502024-03-28 MEDIUM 5.9 CVE-2023-37495 Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino… Domino 14.0+ Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2023-37529 A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious ja… Bigfix Platform 9.5.24 / 10.0.11+ Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2023-37530 A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious ja… Bigfix Platform 9.5.24 / 10.0.11+ Fix from $1,6002024-02-29 MEDIUM 6.5 CVE-2023-28018 HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacke… Connections Mitigation only Fix from $1,6002024-02-12 MEDIUM 6.1 CVE-2023-45698 Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to pr… Sametime Chat And Meetings Mitigation only Fix from $1,6002024-02-10 HIGH 7.5 CVE-2023-45696 Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be sto… Sametime 12.0.2+ Fix from $1,9502024-02-10 HIGH 7.5 CVE-2023-45718 Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web … Sametime 12.0.2+ Fix from $1,9502024-02-09 HIGH 8.8 CVE-2023-50349 Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to… Sametime 12.0.2+ Fix from $1,9502024-02-09