3.2
CVE-2024-30127 - HCL Leap is affected by missing "no cache" headers
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
9.3
CVE-2025-26382 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
9.1
CVE-2025-43859 - h11 accepts some malformed Chunked-Encoding bodies
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires thβ¦
9.2
CVE-2025-43858 - YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS withβ¦
10
CVE-2025-31324 - Missing Authorization check in SAP NetWeaver (Visual Composer development server)
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availabilityβ¦
7.1
CVE-2023-37534 - HCL Leap is affected by a Cross-site scripting (XSS) vulnerability
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
5.3
CVE-2023-45720 - HCL Leap is affected by a disclosure of private personal information vulnerability
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
6.3
CVE-2024-30113 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
3.7
CVE-2024-30114 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
6.5
CVE-2024-30147 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.