4.6
CVE-2022-44759 - HCL Leap is affected by Cross-site scripting (XSS)
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
4.6
CVE-2022-44760 - HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
3.2
CVE-2023-37516 - HCL Leap is affected by missing "no cache" headers
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
3.2
CVE-2024-30127 - HCL Leap is affected by missing "no cache" headers
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
9.3
CVE-2025-26382 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
9.1
CVE-2025-43859 - h11 accepts some malformed Chunked-Encoding bodies
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires thβ¦
9.2
CVE-2025-43858 - YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS withβ¦
10
CVE-2025-31324 - Missing Authorization check in SAP NetWeaver (Visual Composer development server)
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availabilityβ¦
7.1
CVE-2023-37534 - HCL Leap is affected by a Cross-site scripting (XSS) vulnerability
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
5.3
CVE-2023-45720 - HCL Leap is affected by a disclosure of private personal information vulnerability
Insufficient default configuration in HCL Leap allows anonymous access to directory information.