CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
HCL Launch may store certain data for recurring activities in a plain text format.
HCL Launch stores user credentials in plain clear text which can be read by a local user.
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
BigFix Web Reports authorized users may see SMTP credentials in clear text.
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
