Export limit exceeded: 375364 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37508 | 2 Hclsoftware, Hcltech | 2 Devops Plan, Devops Plan | 2026-07-23 | 6.1 Medium |
| HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present. | ||||
| CVE-2023-37507 | 2 Hclsoftware, Hcltech | 2 Devops Plan, Devops Plan | 2026-07-23 | 7.5 High |
| HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | ||||
| CVE-2026-4096 | 2 Hcltech, Ibm | 2 Devops Plan, Devops Plan | 2026-06-16 | 6.5 Medium |
| IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking | ||||
| CVE-2025-36364 | 2 Hcltech, Ibm | 2 Devops Plan, Devops Plan | 2026-03-04 | 6.2 Medium |
| IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. | ||||
| CVE-2025-36363 | 2 Hcltech, Ibm | 2 Devops Plan, Devops Plan | 2026-03-04 | 5.9 Medium |
| IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | ||||
Page 1 of 1.