π¨ CVE-2024-23564
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
π@cveNotify
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL DFXAnalytics - Customer Support
HCL DFXAnalytics is affected by multiple security vulnerabilities.
π¨ CVE-2024-23565
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
π@cveNotify
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23566
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesnβt have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
π@cveNotify
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesnβt have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23567
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
π@cveNotify
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23568
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
π@cveNotify
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23569
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with βX-XSS-Protection" header
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with βX-XSS-Protection" header
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23570
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
π@cveNotify
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23571
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23573
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23574
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23575
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23577
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesnβt adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.
π@cveNotify
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesnβt adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-23578
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-42214
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.
π@cveNotify
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL Aftermarket EPC - Customer Support
HCL Aftermarket EPC is affected by multiple security vulnerabilities.
π¨ CVE-2024-58023
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
π@cveNotify
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
π@cveNotify
π¨ CVE-2024-58330
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
π@cveNotify
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
π@cveNotify
π¨ CVE-2024-58354
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a 'dangerous' checkout of the attacker-submitted pull request code (via the dangerous-git-checkout action) and subsequently executes it (through yarn install and package.json scripts). An attacker can open a pull request whose code runs arbitrary commands with the repository's write-scoped GITHUB_TOKEN, allowing them to push commits, merge or mutate pull requests, add or delete comments, and delete or force-push branches, thereby compromising the repository. The main branch is affected; no patched version is available.
π@cveNotify
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a 'dangerous' checkout of the attacker-submitted pull request code (via the dangerous-git-checkout action) and subsequently executes it (through yarn install and package.json scripts). An attacker can open a pull request whose code runs arbitrary commands with the repository's write-scoped GITHUB_TOKEN, allowing them to push commits, merge or mutate pull requests, add or delete comments, and delete or force-push branches, thereby compromising the repository. The main branch is affected; no patched version is available.
π@cveNotify
GitHub
dynamic booking duration fix Β· calcom/cal.diy@9aa60fa
Scheduling infrastructure for absolutely everyone. - dynamic booking duration fix Β· calcom/cal.diy@9aa60fa
π¨ CVE-2024-14041
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
π@cveNotify
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.
π@cveNotify
GitHub
Fix second constant-time division issue in Kyber Β· bcgit/bc-java@1590247
See also: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/ldX0ThYJuBo/m/uIOqRF5BAwAJ
See also: https://github.com/symbolicsoft/kyber-k2so/commit/2d16efee71ae195a6aef2fb36f5ed60768d78c98
Si...
See also: https://github.com/symbolicsoft/kyber-k2so/commit/2d16efee71ae195a6aef2fb36f5ed60768d78c98
Si...
π¨ CVE-2026-16524
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
π@cveNotify
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
π@cveNotify
π¨ CVE-2026-16526
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
π@cveNotify
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
π@cveNotify
π¨ CVE-2026-16527
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
π@cveNotify
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
π@cveNotify