Hcltech
Hcltech HCL Leap: vulnerabilidades y CVE
Hcltech HCL Leap tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-30127 | Baja (3.2) | 0.16% | — | 24 abr 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
| CVE-2023-37516 | Baja (3.2) | 0.16% | — | 24 abr 2025 | Missing "no cache" headers in HCL Leap permits user directory information to be cached. |
| CVE-2022-44760 | Media (4.6) | 0.29% | — | 24 abr 2025 | Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. |
| CVE-2022-44759 | Media (5.4) | 0.23% | — | 24 abr 2025 | Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. |
| CVE-2024-30147 | Media (6.1) | 0.26% | — | 24 abr 2025 | Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. |
| CVE-2024-30114 | Media (5.4) | 0.24% | — | 24 abr 2025 | Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. |
| CVE-2024-30113 | Media (5.4) | 0.30% | — | 24 abr 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. |
| CVE-2023-45720 | Media (5.3) | 0.31% | — | 24 abr 2025 | Insufficient default configuration in HCL Leap allows anonymous access to directory information. |
| CVE-2023-37534 | Media (6.1) | 0.24% | — | 24 abr 2025 | Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. |
| CVE-2024-30148 | Media (4.1) | 0.27% | — | 24 abr 2025 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem. |
| CVE-2022-38657 | Media (5.4) | 0.29% | — | 12 feb 2023 | An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page. |