Show filters
318 Total Results
Displaying 161-170 of 318
Sort by:
Attacker Value
Unknown
CVE-2021-27774
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
User input included in error response, which could be used in a phishing attack.
0
Attacker Value
Unknown
CVE-2022-27561
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
0
Attacker Value
Unknown
CVE-2022-27560
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
HCL VersionVault Express exposes administrator credentials.
0
Attacker Value
Unknown
CVE-2022-27563
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
0
Attacker Value
Unknown
CVE-2022-27558
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
0
Attacker Value
Unknown
CVE-2022-27546
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
0
Attacker Value
Unknown
CVE-2022-27547
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
0
Attacker Value
Unknown
CVE-2022-27545
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
0
Attacker Value
Unknown
CVE-2022-27544
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may see SMTP credentials in clear text.
0
Attacker Value
Unknown
CVE-2022-31516
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0