Show filters
318 Total Results
Displaying 161-170 of 318
Sort by:
Attacker Value
Unknown

CVE-2021-27774

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
User input included in error response, which could be used in a phishing attack.
Attacker Value
Unknown

CVE-2022-27561

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
Attacker Value
Unknown

CVE-2022-27560

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
HCL VersionVault Express exposes administrator credentials.
Attacker Value
Unknown

CVE-2022-27563

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
Attacker Value
Unknown

CVE-2022-27558

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Attacker Value
Unknown

CVE-2022-27546

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
Attacker Value
Unknown

CVE-2022-27547

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
Attacker Value
Unknown

CVE-2022-27545

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
Attacker Value
Unknown

CVE-2022-27544

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Attacker Value
Unknown

CVE-2022-31516

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.