3.2

CVSS3.1

CVE-2024-30127 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

πŸ“… Published: April 24, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

9.3

CVSS4.0

CVE-2025-26382 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool

Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

πŸ“… Published: April 24, 2025, 7:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-43859 - h11 accepts some malformed Chunked-Encoding bodies

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires th…

πŸ“… Published: April 24, 2025, 6:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS3.1

CVE-2025-43858 - YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with…

πŸ“… Published: April 24, 2025, 6:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-31324 - Missing Authorization check in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability…

πŸ“… Published: April 24, 2025, 4:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2023-37534 - HCL Leap is affected by a Cross-site scripting (XSS) vulnerability

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

πŸ“… Published: April 24, 2025, 4:27 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.

5.3

CVSS3.1

CVE-2023-45720 - HCL Leap is affected by a disclosure of private personal information vulnerability

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

πŸ“… Published: April 24, 2025, 4:25 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.

6.3

CVSS3.1

CVE-2024-30113 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

πŸ“… Published: April 24, 2025, 4:23 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.

3.7

CVSS3.1

CVE-2024-30114 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

πŸ“… Published: April 24, 2025, 4:22 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:47 p.m.

6.5

CVSS3.1

CVE-2024-30147 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

πŸ“… Published: April 24, 2025, 4:21 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.
Total resulsts: 349182
Page 5669 of 34,919
Β« previous page Β» next page
Filters