hcltech

395 tracked vulnerabilities.

CVE-2020-4080 MEDIUM
HCL Domino Verse v10 and v11 - Unauthenticated Stored Cross-Site Scripting via Message Content
Dec 18, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-14232 HIGH
HCL Notes v9 - Authenticated Stack Buffer Overflow via Input Parameter Handling
Dec 18, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-14254 HIGH
HCL BigFix Platform < 10.0.2 - Use of Broken Cryptographic Algorithm via TLS-RSA Cipher Suites
Dec 16, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14248 MEDIUM
BigFix Platform 9.0.0-10.0.2 - Cleartext Transmission of Sensitive Information via Session Cookie
Dec 16, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14268 CRITICAL
HCL Notes 9-10 - Unauthenticated Stack Buffer Overflow via MIME Message Handling
Dec 14, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-14244 CRITICAL
HCL Domino 9.0.0-10.0.0 - Unauthenticated Stack Buffer Overflow via MIME Message Handling
Dec 14, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-4102 MEDIUM
HCL Notes >=9.0.0 <9.0.1 - Buffer Overflow in DXL
Dec 02, 2020
CVSS 6.7
EPSS 0.00
CVE-2020-14260 CRITICAL
HCL Domino 9.0.0-9.0.1 - Buffer Overflow in DXL
Dec 02, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-4128 MEDIUM
HCL Domino - Unauthenticated Lockout Policy Bypass in ID Vault Service
Dec 01, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-4129 MEDIUM
HCL Domino < 9.0.1 - Unauthenticated Lockout Policy Bypass via LDAP Service
Dec 01, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-4126 MEDIUM
HCL iNotes 9.0-10.0.1 - Unauthenticated Sensitive Cookie Exposure via HTTP Session Interception
Dec 01, 2020
CVSS 5.9
EPSS 0.00
CVE-2020-4127 MEDIUM
HCL Domino < 9.0.1 - Cross-Site Request Forgery in Login
Nov 30, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-14258 HIGH
HCL Notes 9-11 - Unauthenticated Denial of Service via Crafted Email Message
Nov 21, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14234 HIGH
HCL Domino < 9.0.1 FP10 IF6 and < 10.0.1 - Denial of Service via Improper Input Validation
Nov 21, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14230 HIGH
HCL Domino - Denial of Service via Crafted Email Message
Nov 21, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-4097 MEDIUM
HCL Notes 9.0-9.0.1, 10.0-10.0.1, 11.0-11.0.1 - Buffer Overflow via Input Parameter Handling
Nov 05, 2020
CVSS 6.8
EPSS 0.00
CVE-2020-14240 MEDIUM
HCL Notes < 9.0.1 FP10 IF8, 10.0.1 < FP6, 11.0.1 < FP1 - Stored Cross-Site Scripting
Nov 05, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-14222 MEDIUM
HCL Digital Experience 8.5, 9.0, 9.5 - Reflected Cross-Site Scripting
Nov 05, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-14223 MEDIUM
HCL Digital Experience 8.5, 9.0, 9.5 - Reflected Cross-Site Scripting
Oct 01, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-4104 MEDIUM
HCL BigFix WebUI - Stored Cross-Site Scripting in Apps->Software Module
Jul 17, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-4095 MEDIUM
HCL BigFix Platform 9.2-9.2.18 - Insufficiently Protected Credentials in Memory
Jul 16, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-4089 MEDIUM
HCL Notes 9-11 - Information Leakage via Mailto Protocol Handler
Jun 26, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-4101 CRITICAL
HCL Digital Experience - Server-Side Request Forgery
Jun 11, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-4092 MEDIUM
HCL Nomad - Cleartext Transmission of Sensitive Information
May 06, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-4085 MEDIUM
HCL Connections - Information Disclosure via Stack Trace
Apr 22, 2020
CVSS 6.5
EPSS 0.00