Show filters
287 Total Results
Displaying 51-60 of 287
Sort by:
Attacker Value
Unknown
CVE-2024-30120
Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.
0
Attacker Value
Unknown
CVE-2024-30119
Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
0
Attacker Value
Unknown
CVE-2023-45707
Disclosure Date: June 08, 2024 (last updated June 09, 2024)
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
0
Attacker Value
Unknown
CVE-2023-37539
Disclosure Date: June 06, 2024 (last updated July 17, 2024)
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
0
Attacker Value
Unknown
CVE-2024-23580
Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown
CVE-2024-23579
Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown
CVE-2024-23556
Disclosure Date: May 18, 2024 (last updated May 18, 2024)
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
0
Attacker Value
Unknown
CVE-2024-23554
Disclosure Date: May 18, 2024 (last updated May 18, 2024)
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
0
Attacker Value
Unknown
CVE-2024-23583
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
0
Attacker Value
Unknown
CVE-2024-23576
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
0