Hcltech
hcltech
427 CVEs • 100 products
Products (100)
Click to collapseToggle
Products (100)
Click to collapse
CVEs (427)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hcltech 1Traveler For Microsoft Outlook Jun 17, 2026 May 30, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. |
1Hcltech 1Traveler For Microsoft Outlook Jun 17, 2026 May 30, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. |
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissio...Show more |
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requ...Show more |
Improper access control of endpoint in HCL Domino Leap
allows certain admin users to import applications from the
server's filesystem. |
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side
script injection in the authoring environment and deployed applications. |
Insufficient sanitization policy in HCL Leap
allows client-side script injection in the deployed application through the
HTML widget. |
Insufficient default configuration in HCL Leap
allows anonymous access to directory information. |
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap
allow script injection through query parameters. |
Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. |
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications |
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. |
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts. |
Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
Missing "no cache" headers in HCL Leap permits user directory information to be cached. |
Unsafe default file type filter policy in HCL
Leap allows execution of unsafe JavaScript in deployed applications. |
Improper sanitization of SVG files in HCL Leap
allows client-side script injection in deployed applications. |
Multiple vectors in HCL Leap allow client-side
script injection in the authoring environment and deployed applications. |
Insufficient sanitization in HCL Leap allows
client-side script injection in the authoring environment. |