cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2021-27759,https://securityvulnerability.io/vulnerability/CVE-2021-27759,,This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.,Hcl Software,Hcl Bigfix Inventory,2.3,LOW,0.0005300000193528831,false,false,false,false,,false,false,2022-05-06T18:15:00.000Z,0 CVE-2021-27758,https://securityvulnerability.io/vulnerability/CVE-2021-27758,,There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.,Hcl Software,Hcl Bigfix Inventory,4.3,MEDIUM,0.0005300000193528831,false,false,false,false,,false,false,2022-05-06T18:15:00.000Z,0 CVE-2020-14248,https://securityvulnerability.io/vulnerability/CVE-2020-14248,,"BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.",HCL Software,Hcl Bigfix Inventory,5.3,MEDIUM,0.0015399999683722854,false,false,false,false,,false,false,2020-12-16T14:11:34.000Z,0 CVE-2020-14254,https://securityvulnerability.io/vulnerability/CVE-2020-14254,,TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.,HCL Software,Hcl Bigfix Inventory,7.5,HIGH,0.002199999988079071,false,false,false,false,,false,false,2020-12-16T14:07:42.000Z,0