8.7

CVSS4.0

CVE-2025-4140 - Netgear EX6120 sub_30394 buffer overflow

A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure b…

πŸ“… Published: April 30, 2025, 9:31 p.m. πŸ”„ Last Modified: May 12, 2025, 7:40 p.m.

4.1

CVSS3.1

CVE-2024-30146 - HCL Domino Leap is affected by improper access control

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

πŸ“… Published: April 30, 2025, 9:16 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:06 a.m.

6.5

CVSS3.1

CVE-2024-30145 - HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

πŸ“… Published: April 30, 2025, 9:15 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 4:17 p.m.

6.3

CVSS3.1

CVE-2024-30115 - HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

πŸ“… Published: April 30, 2025, 9:14 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 1:41 a.m.

5.3

CVSS3.1

CVE-2023-45721 - HCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulner…

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

πŸ“… Published: April 30, 2025, 9:13 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 1:41 a.m.

7.1

CVSS3.1

CVE-2023-37535 - HCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerability

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

πŸ“… Published: April 30, 2025, 9:12 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:34 p.m.

3.2

CVSS3.1

CVE-2023-37517 - HCL Domino Volt and Domino Leap are affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

πŸ“… Published: April 30, 2025, 9:11 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:35 p.m.

4.6

CVSS3.1

CVE-2022-42450 - HCL Domino Volt is affected by Cross-site scripting (XSS)

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

πŸ“… Published: April 30, 2025, 9:07 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:36 p.m.

4.6

CVSS3.1

CVE-2022-42449 - HCL Domino Volt is affected by an unrestricted upload of a dangerous file type

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

πŸ“… Published: April 30, 2025, 9:01 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:40 p.m.

4.6

CVSS3.1

CVE-2022-27562 - HCL Domino Volt is affected by an unrestricted upload of a dangerous file type

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

πŸ“… Published: April 30, 2025, 8:54 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 8:41 p.m.
Total resulsts: 349182
Page 5621 of 34,919
Β« previous page Β» next page
Filters