📦

hcl_leap

Vendor: hcltech

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 21 Total Indexed
Avg. EPSS 0.24% Exploit Prob.
Latest CVE CVE-2024-30127 Apr 24

Security Vulnerability Index

Page 1 / 3
3.2 CVSS

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

EPSS: 0.15%
3.2 CVSS

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

EPSS: 0.15%
4.6 CVSS

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

EPSS: 0.27%
4.6 CVSS

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

EPSS: 0.22%
6.5 CVSS

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

EPSS: 0.25%
3.7 CVSS

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

EPSS: 0.23%
6.3 CVSS

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

EPSS: 0.29%
5.3 CVSS

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

EPSS: 0.30%
7.1 CVSS

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

EPSS: 0.23%
4.1 CVSS

Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

EPSS: 0.26%