3.1

CVSS3.1

CVE-2025-59854 - HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robuโ€ฆ

๐Ÿ“… Published: May 6, 2026, 10:27 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

3.1

CVSS3.1

CVE-2025-59853 - HCL DFXAnalytics is affected by an Improper Error Handling vulnerability

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.

๐Ÿ“… Published: May 6, 2026, 10:26 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

3.7

CVSS3.1

CVE-2025-59852 - HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

๐Ÿ“… Published: May 6, 2026, 10:25 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

3.7

CVSS3.1

CVE-2025-59851 - HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to gain unauthorized access or compromise the applicโ€ฆ

๐Ÿ“… Published: May 6, 2026, 10:24 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

5.3

CVSS3.1

CVE-2025-31970 - HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)

๐Ÿ“… Published: May 6, 2026, 10:22 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

6.3

CVSS3.1

CVE-2026-6420 - Keylime: keylime: security bypass due to hardcoded tpm quote nonce

A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographicโ€ฆ

๐Ÿ“… Published: May 6, 2026, 10 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:24 p.m.

6.9

CVSS4.0

CVE-2026-6860 - Wildcard Server Name Misuse in TLS Handshake Enables Client to Connect to Any Subdomain

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

๐Ÿ“… Published: May 6, 2026, 9:55 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 2:51 p.m.

7.5

CVSS3.1

CVE-2026-1719 - Gravity Bookings <= 2.5.9 - Unauthenticated SQL Injection via 'category_id' Parameter

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackersโ€ฆ

๐Ÿ“… Published: May 6, 2026, 9:27 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

5.2

CVSS3.1

CVE-2026-40001 - Local privilege escalation vulnerability in ZTE PROCESS Guard service of the cloud computer client

There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traversal bypass.

๐Ÿ“… Published: May 6, 2026, 8:48 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 9:25 p.m.

9.1

CVSS3.1

CVE-2026-40010 - Apache Wicket: possible session fixation using AuthenticatedWebSession

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for aย session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version โ€ฆ

๐Ÿ“… Published: May 6, 2026, 8:34 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 12:19 p.m.
Total resulsts: 349182
Page 79 of 34,919
ยซ previous page ยป next page
Filters