CVE Alert: CVE-2023-37534
Vulnerability Summary: CVE-2023-37534 Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. Affected Endpoints: No affected...
Vulnerability Summary: CVE-2023-37534 Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. Affected Endpoints: No affected...
Vulnerability Summary: CVE-2023-45720 Insufficient default configuration in HCL Leap allows anonymous access to directory information. Affected Endpoints: No affected endpoints...
Vulnerability Summary: CVE-2024-30147 Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. Affected...
Vulnerability Summary: CVE-2022-44760 Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications....
Vulnerability Summary: CVE-2022-44759 Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. Affected Endpoints:...
Vulnerability Summary: CVE-2025-1294 The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all...
Vulnerability Summary: CVE-2023-37516 Missing "no cache" headers in HCL Leap permits user directory information to be cached. Affected Endpoints: No...
Vulnerability Summary: CVE-2024-30127 Missing "no cache" headers in HCL Leap permits sensitive data to be cached. Affected Endpoints: No affected...
Vulnerability Summary: CVE-2025-46275 WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without...
Vulnerability Summary: CVE-2025-43861 ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable...
Vulnerability Summary: CVE-2025-46274 UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in...
Vulnerability Summary: CVE-2025-46271 UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or...
Vulnerability Summary: CVE-2025-46272 WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to...
Vulnerability Summary: CVE-2025-3749 The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in...
Vulnerability Summary: CVE-2025-46273 UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS...
Vulnerability Summary: CVE-2025-45428 In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability,...
Vulnerability Summary: CVE-2025-1054 The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site...
Vulnerability Summary: CVE-2024-10306 A vulnerability was found in mod_proxy_cluster. The issue is that the directive should be replaced by the...
Vulnerability Summary: CVE-2025-2703 The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions...
Vulnerability Summary: CVE-2025-43716 A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the...
Vulnerability Summary: CVE-2024-47829 pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function...
Vulnerability Summary: CVE-2025-43965 In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. Affected...
Vulnerability Summary: CVE-2025-21605 Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and...
Vulnerability Summary: CVE-2025-45427 In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability,...