4.6

CVSS3.1

CVE-2022-44759 - HCL Leap is affected by Cross-site scripting (XSS)

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

πŸ“… Published: April 24, 2025, 8:38 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

4.6

CVSS3.1

CVE-2022-44760 - HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

3.2

CVSS3.1

CVE-2023-37516 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

3.2

CVSS3.1

CVE-2024-30127 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

πŸ“… Published: April 24, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

9.3

CVSS4.0

CVE-2025-26382 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool

Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

πŸ“… Published: April 24, 2025, 7:47 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

9.1

CVSS3.1

CVE-2025-43859 - h11 accepts some malformed Chunked-Encoding bodies

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires th…

πŸ“… Published: April 24, 2025, 6:15 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

9.2

CVSS3.1

CVE-2025-43858 - YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with…

πŸ“… Published: April 24, 2025, 6:04 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

10

CVSS3.1

CVE-2025-31324 - Missing Authorization check in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability…

πŸ“… Published: April 24, 2025, 4:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2023-37534 - HCL Leap is affected by a Cross-site scripting (XSS) vulnerability

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

πŸ“… Published: April 24, 2025, 4:27 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.

5.3

CVSS3.1

CVE-2023-45720 - HCL Leap is affected by a disclosure of private personal information vulnerability

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

πŸ“… Published: April 24, 2025, 4:25 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.
Total resulsts: 344064
Page 5157 of 34,407
Β« previous page Β» next page
Filters