6.5
CVE-2024-30145 - HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
6.3
CVE-2024-30115 - HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
5.3
CVE-2023-45721 - HCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerβ¦
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
7.1
CVE-2023-37535 - HCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerability
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
3.2
CVE-2023-37517 - HCL Domino Volt and Domino Leap are affected by missing "no cache" headers
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
4.6
CVE-2022-42450 - HCL Domino Volt is affected by Cross-site scripting (XSS)
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
4.6
CVE-2022-42449 - HCL Domino Volt is affected by an unrestricted upload of a dangerous file type
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
4.6
CVE-2022-27562 - HCL Domino Volt is affected by an unrestricted upload of a dangerous file type
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
6.5
CVE-2025-30422 -
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
6.5
CVE-2025-24132 -
The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.