Search Results (12 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30146 1 Hcltech 1 Domino Leap 2025-12-31 4.1 Medium
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
CVE-2024-30145 1 Hcltech 1 Domino Leap 2025-11-07 6.5 Medium
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2023-45721 1 Hcltech 1 Domino Leap 2025-11-04 5.3 Medium
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
CVE-2024-30115 1 Hcltech 1 Domino Leap 2025-11-04 6.3 Medium
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
CVE-2022-27562 1 Hcltech 1 Domino Leap 2025-10-30 4.6 Medium
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
CVE-2022-42449 1 Hcltech 1 Domino Leap 2025-10-30 4.6 Medium
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
CVE-2022-42450 1 Hcltech 1 Domino Leap 2025-10-30 4.6 Medium
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
CVE-2023-37517 1 Hcltech 1 Domino Leap 2025-10-30 3.2 Low
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2023-37535 1 Hcltech 1 Domino Leap 2025-10-30 7.1 High
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
CVE-2022-27558 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 5.9 Medium
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
CVE-2022-27547 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 6.1 Medium
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
CVE-2022-27546 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 8.3 High
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.