Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hcltech vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2019-4091
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
Hcltech Marketing Campaign 9.1.2.4
Hcltech Marketing Campaign
5.3
CVSSv3
CVE-2021-27780
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Hcltech Modern Client Management
Hcltech Bigfix Mobile
4.8
CVSSv3
CVE-2021-27781
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
Hcltech Modern Client Management
Hcltech Bigfix Mobile
5.4
CVSSv3
CVE-2024-23553
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
Hcltech Bigfix Platform 11.0.0
Hcltech Bigfix Platform
5.4
CVSSv3
CVE-2019-4090
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
Hcltech Marketing Campaign
Hcltech Marketing Campaign 11.0.1
7.5
CVSSv3
CVE-2022-27558
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Hcltech Hcl Inotes 12.0.1
Hcltech Domino 12.0.1
5.5
CVSSv3
CVE-2021-27760
An issue exists in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
Hcltech Hcl Inotes 11.0.1
Hcltech Hcl Inotes 11.0.0
6.5
CVSSv3
CVE-2022-27560
HCL VersionVault Express exposes administrator credentials.
Hcltech Versionvault Express 2.0.1
Hcltech Versionvault Express 2.1.0
7.5
CVSSv3
CVE-2022-27563
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
Hcltech Versionvault Express 2.0.1
Hcltech Versionvault Express 2.1.0
7.5
CVSSv3
CVE-2021-27784
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
Hcltech Hcl Launch Container Image
Hcltech Hcl Launch Container Image 7.1.0.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »