📦

domino_leap

Vendor: hcltech

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 0.24% Exploit Prob.
Latest CVE CVE-2024-30146 Apr 30

Security Vulnerability Index

Page 1 / 2
4.1 CVSS

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

EPSS: 0.20%
6.5 CVSS

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

EPSS: 0.25%
6.3 CVSS

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

EPSS: 0.24%
5.3 CVSS

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

EPSS: 0.30%
7.1 CVSS

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

EPSS: 0.23%
3.2 CVSS

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

EPSS: 0.22%
4.6 CVSS

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

EPSS: 0.22%
4.6 CVSS

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

EPSS: 0.27%
4.6 CVSS

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

EPSS: 0.27%