VYPR
Vendor

HCL Software

Products
151
CVEs
623
Across products
497
Status
Private

Products

151
View all 151 products →

Recent CVEs

623
View all 623 CVEs →
  • CVE-2026-67100CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.00

    HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain…

  • CVE-2025-62319CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently…

  • CVE-2022-44755CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44754CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44753CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44752CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44751CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44750CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2020-14245CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.

  • CVE-2020-14275CriJan 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2020-14224CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which…

  • CVE-2020-14268CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which…

  • CVE-2020-14244CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which…

  • CVE-2020-14260CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.

  • CVE-2020-4101CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

  • CVE-2019-4393CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard is vulnerable to excessive authorization attempts

  • CVE-2019-4392CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

  • CVE-2022-42447CriApr 2, 2023
    risk 0.62cvss 9.6epss 0.00

    HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.

  • CVE-2026-67101CriSep 18, 2026
    risk 0.60cvss 9.3epss 0.00

    HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

  • CVE-2023-37538CriOct 11, 2023
    risk 0.60cvss 9.3epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).