Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-37528 A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application… Bigfix Platform 9.5.24 / 10.0.11+ Fix from $1,6002024-02-03 MEDIUM 5.4 CVE-2024-23553 A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. Bigfix Platform 9.5.24 / 10.0.11+ Fix from $1,6002024-02-02 MEDIUM 6.1 CVE-2023-37527 A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute ma… Bigfix Platform 9.5.24 / 10.0.11+ Fix from $1,6002024-02-02 HIGH 8.8 CVE-2023-37518 HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the … Bigfix Servicenow Data Flow 1.3+ Fix from $1,9502024-01-30 MEDIUM 6.5 CVE-2023-50343 HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 5.4 CVE-2023-50344 HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 HIGH 7.5 CVE-2023-50341 HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl… Dryice Myxalytics Mitigation only Fix from $1,9502024-01-03 CRITICAL 9.8 CVE-2023-45722 HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-45723 HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-45724 HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file with… Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 CRITICAL 9.1 CVE-2023-50351 HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or i… Dryice Myxalytics No fix yet Fix from $2,3002024-01-03 HIGH 7.5 CVE-2023-50350 HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt se… Dryice Myxalytics Mitigation only Fix from $1,9502024-01-03 MEDIUM 5.3 CVE-2023-50348 HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an at… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 6.1 CVE-2023-50345 HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially l… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 6.1 CVE-2023-37520 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltrati… Bigfix Platform 9.5.23 / 10.0.10+ Fix from $1,6002023-12-21 MEDIUM 6.1 CVE-2023-37519 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigF… Bigfix Platform 9.5.23 / 10.0.10+ Fix from $1,6002023-12-21 MEDIUM 6.5 CVE-2023-28022 HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl… Connections Mitigation only Fix from $1,6002023-12-15 MEDIUM 5.4 CVE-2023-28017 HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow… Connections Patch available Fix from $1,6002023-12-07 MEDIUM 6.1 CVE-2023-37533 HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in… Connections Mitigation only Fix from $1,6002023-11-09 CRITICAL 9.8 CVE-2023-37503 HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts. Hcl Compass 2.2.3+ Fix from $2,3002023-10-19 MEDIUM 6.5 CVE-2023-37504 HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionalit… Hcl Compass 2.2.3+ Fix from $1,6002023-10-19 HIGH 8.8 CVE-2023-37502 HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server … Hcl Compass 2.2.3+ Fix from $1,9502023-10-18 HIGH 7.8 CVE-2023-37537 An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attac… Appscan Presence after 2.1.37 Fix from $1,9502023-10-17 MEDIUM 6.1 CVE-2023-37538 HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker m… Digital Experience Patch available Fix from $1,6002023-10-11 HIGH 8.2 CVE-2022-44757 BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to se… Bigfix Insights For Vulnerability Remediation 2.0.3+ Fix from $1,9502023-10-11 MEDIUM 5.3 CVE-2022-44758 BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not e… Bigfix Insights For Vulnerability Remediation 2.0.3+ Fix from $1,6002023-10-11 MEDIUM 5.3 CVE-2023-28010 In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. Domino Mitigation only Fix from $1,6002023-09-08 MEDIUM 5.5 CVE-2023-37512 When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive infor… Traveler Companion 12.0.6+ Fix from $1,6002023-08-11 MEDIUM 5.5 CVE-2023-37513 When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive infor… Traveler To Do 12.0.6+ Fix from $1,6002023-08-11 HIGH 7.1 CVE-2023-23342 If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented.  Hcl Nomad 1.0.7+ Fix from $1,9502023-08-10