Show filters
287 Total Results
Displaying 51-60 of 287
Sort by:
Attacker Value
Unknown

CVE-2024-30120

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.
0
Attacker Value
Unknown

CVE-2024-30119

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.
0
Attacker Value
Unknown

CVE-2023-45707

Disclosure Date: June 08, 2024 (last updated June 09, 2024)
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
0
Attacker Value
Unknown

CVE-2023-37539

Disclosure Date: June 06, 2024 (last updated July 17, 2024)
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
Attacker Value
Unknown

CVE-2024-23580

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown

CVE-2024-23579

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown

CVE-2024-23556

Disclosure Date: May 18, 2024 (last updated May 18, 2024)
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
0
Attacker Value
Unknown

CVE-2024-23554

Disclosure Date: May 18, 2024 (last updated May 18, 2024)
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
0
Attacker Value
Unknown

CVE-2024-23583

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
0
Attacker Value
Unknown

CVE-2024-23576

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
0