Vulnerabilities (CVE)

Total 398469 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23563 1 Hcltech 1 Connections Docs 2026-06-17 N/A 3.9 LOW
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2024-23562 1 Hcltech 1 Domino 2026-06-17 N/A 5.3 MEDIUM
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.
CVE-2024-23561 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 4.3 MEDIUM
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
CVE-2024-23560 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 4.4 MEDIUM
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
CVE-2024-23559 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 6.1 MEDIUM
HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
CVE-2024-23558 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 6.3 MEDIUM
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
CVE-2024-23557 1 Hcltech 1 Connections 2026-06-17 N/A 3.5 LOW
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.
CVE-2024-23556 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 5.9 MEDIUM
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
CVE-2024-23554 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 5.7 MEDIUM
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
CVE-2024-23553 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 3.0 LOW
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
CVE-2024-23551 2026-06-17 N/A 6.5 MEDIUM
Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe consequences such as data breaches, unauthorized data manipulation, and compromised system integrity.
CVE-2024-23550 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 6.2 MEDIUM
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
CVE-2024-23540 2026-06-17 N/A 5.3 MEDIUM
The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.
CVE-2024-23539 1 Apache 1 Fineract 2026-06-17 N/A 8.3 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
CVE-2024-23538 1 Apache 1 Fineract 2026-06-17 N/A 9.9 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
CVE-2024-23537 1 Apache 1 Fineract 2026-06-17 N/A 8.4 HIGH
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
CVE-2024-23535 1 Ivanti 1 Avalanche 2026-06-17 N/A 8.8 HIGH
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
CVE-2024-23534 1 Ivanti 1 Avalanche 2026-06-17 N/A 8.8 HIGH
An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
CVE-2024-23533 1 Ivanti 1 Avalanche 2026-06-17 N/A 6.5 MEDIUM
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
CVE-2024-23532 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.