HCL Software
Products
151- 46 CVEs
- 36 CVEs
- 32 CVEs
- 29 CVEs
- 27 CVEs
- 25 CVEs
- 24 CVEs
- 19 CVEs
- 18 CVEs
- 18 CVEs
- 17 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 14 CVEs
- 14 CVEs
- 14 CVEs
- 12 CVEs
- 11 CVEs
- 11 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- View all 151 products →
Recent CVEs
623| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67100 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain… | ||
| CVE-2025-62319 | Cri | 0.64 | 9.8 | 0.00 | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently… | ||
| CVE-2022-44755 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44754 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44753 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44752 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44751 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44750 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2020-14245 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2021 | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. | ||
| CVE-2020-14275 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2021 | Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. | ||
| CVE-2020-14224 | Cri | 0.64 | 9.8 | 0.02 | Dec 18, 2020 | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which… | ||
| CVE-2020-14268 | Cri | 0.64 | 9.8 | 0.02 | Dec 14, 2020 | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which… | ||
| CVE-2020-14244 | Cri | 0.64 | 9.8 | 0.03 | Dec 14, 2020 | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which… | ||
| CVE-2020-14260 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system. | ||
| CVE-2020-4101 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2020 | "HCL Digital Experience is susceptible to Server Side Request Forgery." | ||
| CVE-2019-4393 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2020 | HCL AppScan Standard is vulnerable to excessive authorization attempts | ||
| CVE-2019-4392 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | ||
| CVE-2022-42447 | Cri | 0.62 | 9.6 | 0.00 | Apr 2, 2023 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. | ||
| CVE-2026-67101 | Cri | 0.60 | 9.3 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | ||
| CVE-2023-37538 | Cri | 0.60 | 9.3 | 0.00 | Oct 11, 2023 | HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). |
- risk 0.64cvss 9.8epss 0.00
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain…
- risk 0.64cvss 9.8epss 0.00
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
- risk 0.64cvss 9.8epss 0.01
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which…
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.
- risk 0.64cvss 9.8epss 0.01
"HCL Digital Experience is susceptible to Server Side Request Forgery."
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard is vulnerable to excessive authorization attempts
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
- risk 0.62cvss 9.6epss 0.00
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
- risk 0.60cvss 9.3epss 0.00
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
- risk 0.60cvss 9.3epss 0.00
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).