Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hcltech vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-37527
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an malicious user to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web pag...
Hcltech Bigfix Platform 11.0.0
Hcltech Bigfix Platform
NA
CVE-2023-37528
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
Hcltech Bigfix Platform 11.0.0
Hcltech Bigfix Platform
NA
CVE-2024-23553
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
Hcltech Bigfix Platform 11.0.0
Hcltech Bigfix Platform
NA
CVE-2022-27558
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Hcltech Hcl Inotes 12.0.1
Hcltech Domino 12.0.1
3.5
CVSSv2
CVE-2019-4090
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
Hcltech Marketing Campaign
Hcltech Marketing Campaign 11.0.1
3.5
CVSSv2
CVE-2019-4091
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
Hcltech Marketing Campaign 9.1.2.4
Hcltech Marketing Campaign
NA
CVE-2022-27560
HCL VersionVault Express exposes administrator credentials.
Hcltech Versionvault Express 2.0.1
Hcltech Versionvault Express 2.1.0
NA
CVE-2022-27563
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
Hcltech Versionvault Express 2.0.1
Hcltech Versionvault Express 2.1.0
6
CVSSv2
CVE-2021-27760
An issue exists in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
Hcltech Hcl Inotes 11.0.1
Hcltech Hcl Inotes 11.0.0
NA
CVE-2021-27784
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
Hcltech Hcl Launch Container Image
Hcltech Hcl Launch Container Image 7.1.0.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »