Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31961 1 Hcltech 1 Connections 2026-06-17 N/A 3.7 LOW
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
CVE-2025-31960 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
CVE-2025-31959 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.5 LOW
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
CVE-2025-31958 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.7 LOW
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.
CVE-2025-31957 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 2.6 LOW
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.
CVE-2025-31955 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.6 HIGH
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
CVE-2025-31954 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 5.4 MEDIUM
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
CVE-2025-31953 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
CVE-2025-31952 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVE-2025-31951 2026-06-17 N/A 8.8 HIGH
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.
CVE-2025-31950 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain EV charger energy consumption information of other users.
CVE-2025-31949 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An authenticated attacker can obtain any plant name by knowing the plant ID.
CVE-2025-31948 2026-06-17 N/A 3.3 LOW
Improper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2025-31947 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 5.8 MEDIUM
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
CVE-2025-31946 2026-06-17 N/A 6.2 MEDIUM
Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash.
CVE-2025-31945 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain other users' charger information.
CVE-2025-31944 2026-06-17 N/A 5.3 MEDIUM
Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
CVE-2025-31941 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
CVE-2025-31940 2026-06-17 N/A 6.7 MEDIUM
Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2025-31937 1 Intel 1 Quickassist Technology 2026-06-17 N/A 5.6 MEDIUM
Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.