cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2017-1659,https://securityvulnerability.io/vulnerability/CVE-2017-1659,,"""HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.""",IBM,"""hcl Inotes""",6.1,MEDIUM,0.0007200000109151006,false,,false,false,false,,,false,false,,2020-07-01T13:45:17.000Z,0 CVE-2013-0594,https://securityvulnerability.io/vulnerability/CVE-2013-0594,,Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.,IBM,Inotes,6.1,MEDIUM,0.0009699999936856329,false,,false,false,false,,,false,false,,2018-07-11T16:00:00.000Z,0 CVE-2013-0592,https://securityvulnerability.io/vulnerability/CVE-2013-0592,,Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.,IBM,Inotes,5.4,MEDIUM,0.0006000000284984708,false,,false,false,false,,,false,false,,2018-07-11T16:00:00.000Z,0 CVE-2013-0589,https://securityvulnerability.io/vulnerability/CVE-2013-0589,,IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371.,IBM,Inotes,7.5,HIGH,0.001820000004954636,false,,false,false,false,,,false,false,,2018-07-11T16:00:00.000Z,0 CVE-2017-1421,https://securityvulnerability.io/vulnerability/CVE-2017-1421,,IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.,IBM,Inotes,6.1,MEDIUM,0.001449999981559813,false,,false,false,false,,,false,false,,2017-12-13T18:29:00.000Z,0 CVE-2017-1327,https://securityvulnerability.io/vulnerability/CVE-2017-1327,,IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062.,IBM,Inotes,6.1,MEDIUM,0.00107999995816499,false,,false,false,false,,,false,false,,2017-08-03T15:29:00.000Z,0 CVE-2017-1332,https://securityvulnerability.io/vulnerability/CVE-2017-1332,,IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234.,IBM,Inotes,6.1,MEDIUM,0.0009599999757483602,false,,false,false,false,,,false,false,,2017-07-31T21:29:00.000Z,0 CVE-2017-1214,https://securityvulnerability.io/vulnerability/CVE-2017-1214,,"IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854.",IBM,Inotes,5.7,MEDIUM,0.0008800000068731606,false,,false,false,false,,,false,false,,2017-06-12T19:00:00.000Z,0 CVE-2017-1325,https://securityvulnerability.io/vulnerability/CVE-2017-1325,,IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125976.,IBM,Inotes,6.1,MEDIUM,0.0012100000167265534,false,,false,false,false,,,false,false,,2017-05-26T16:00:00.000Z,0 CVE-2016-9990,https://securityvulnerability.io/vulnerability/CVE-2016-9990,,IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.,IBM,Inotes,6.1,MEDIUM,0.0009899999713525176,false,,false,false,false,,,false,false,,2017-03-31T18:00:00.000Z,0 CVE-2016-5883,https://securityvulnerability.io/vulnerability/CVE-2016-5883,,IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010.,IBM,Inotes,6.1,MEDIUM,0.0012100000167265534,false,,false,false,false,,,false,false,,2017-02-23T16:00:00.000Z,0 CVE-2016-5881,https://securityvulnerability.io/vulnerability/CVE-2016-5881,,IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.,IBM,Inotes,6.1,MEDIUM,0.0009899999713525176,false,,false,false,false,,,false,false,,2017-02-01T22:00:00.000Z,0 CVE-2016-0282,https://securityvulnerability.io/vulnerability/CVE-2016-0282,,"Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.",IBM,Lotus Inotes,5.4,MEDIUM,0.0008200000156648457,false,,false,false,false,,,false,false,,2016-11-24T19:41:00.000Z,0 CVE-2014-0913,https://securityvulnerability.io/vulnerability/CVE-2014-0913,,"Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.",IBM,"Lotus Inotes,Lotus Domino",,,0.001769999973475933,false,,false,false,false,,,false,false,,2014-05-09T01:00:00.000Z,0 CVE-2013-4064,https://securityvulnerability.io/vulnerability/CVE-2013-4064,,"Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.",IBM,"Lotus Domino,Lotus Inotes",,,0.0006200000061653554,false,,false,false,false,,,false,false,,2013-12-21T11:00:00.000Z,0 CVE-2013-4063,https://securityvulnerability.io/vulnerability/CVE-2013-4063,,"Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.",IBM,"Lotus Domino,Lotus Inotes",,,0.0012199999764561653,false,,false,false,false,,,false,false,,2013-12-21T11:00:00.000Z,0 CVE-2013-4065,https://securityvulnerability.io/vulnerability/CVE-2013-4065,,"Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.",IBM,"Lotus Domino,Lotus Inotes",,,0.0012199999764561653,false,,false,false,false,,,false,false,,2013-12-21T11:00:00.000Z,0 CVE-2013-4068,https://securityvulnerability.io/vulnerability/CVE-2013-4068,,"Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8.",IBM,"Lotus Domino,Lotus Inotes",,,0.02198999933898449,false,,false,false,false,,,false,false,,2013-09-20T15:00:00.000Z,0 CVE-2013-0595,https://securityvulnerability.io/vulnerability/CVE-2013-0595,,"Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3.",IBM,"Lotus Inotes,Lotus Domino",,,0.001769999973475933,false,,false,false,false,,,false,false,,2013-08-27T01:00:00.000Z,0 CVE-2013-0591,https://securityvulnerability.io/vulnerability/CVE-2013-0591,,"Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590.",IBM,"Lotus Inotes,Lotus Domino",,,0.0006200000061653554,false,,false,false,false,,,false,false,,2013-08-27T01:00:00.000Z,0 CVE-2013-0590,https://securityvulnerability.io/vulnerability/CVE-2013-0590,,"Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0591.",IBM,"Lotus Inotes,Lotus Domino",,,0.0006200000061653554,false,,false,false,false,,,false,false,,2013-08-27T01:00:00.000Z,0 CVE-2013-0536,https://securityvulnerability.io/vulnerability/CVE-2013-0536,,"ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.",IBM,"Lotus Inotes,Lotus Notes,Lotus Notes Traveler",,,0.0004199999966658652,false,,false,false,false,,,false,false,,2013-06-21T17:00:00.000Z,0 CVE-2012-5943,https://securityvulnerability.io/vulnerability/CVE-2012-5943,,"Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.",IBM,Lotus Inotes,,,0.0012199999764561653,false,,false,false,false,,,false,false,,2013-03-26T21:00:00.000Z,0 CVE-2013-0525,https://securityvulnerability.io/vulnerability/CVE-2013-0525,,"Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.",IBM,Lotus Inotes,,,0.0004900000058114529,false,,false,false,false,,,false,false,,2013-03-26T21:00:00.000Z,0 CVE-2012-2175,https://securityvulnerability.io/vulnerability/CVE-2012-2175,,Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.,IBM,Lotus Inotes,,,0.9726300239562988,false,,false,false,false,,,false,false,,2012-06-20T10:00:00.000Z,0