HCL Software
Products
149- 46 CVEs
- 33 CVEs
- 32 CVEs
- 27 CVEs
- 24 CVEs
- 23 CVEs
- 18 CVEs
- 17 CVEs
- 17 CVEs
- 16 CVEs
- 15 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 14 CVEs
- 14 CVEs
- 12 CVEs
- 12 CVEs
- 11 CVEs
- 11 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 7 CVEs
- 7 CVEs
- View all 149 products →
Recent CVEs
580| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-62319 | Cri | 0.64 | 9.8 | 0.00 | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently… | ||
| CVE-2022-44755 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44754 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44753 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44752 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44751 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44750 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2020-14245 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2021 | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. | ||
| CVE-2020-14224 | Cri | 0.64 | 9.8 | 0.02 | Dec 18, 2020 | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which… | ||
| CVE-2020-14268 | Cri | 0.64 | 9.8 | 0.02 | Dec 14, 2020 | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which… | ||
| CVE-2020-14244 | Cri | 0.64 | 9.8 | 0.03 | Dec 14, 2020 | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which… | ||
| CVE-2020-14260 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system. | ||
| CVE-2020-4101 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2020 | "HCL Digital Experience is susceptible to Server Side Request Forgery." | ||
| CVE-2019-4393 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2020 | HCL AppScan Standard is vulnerable to excessive authorization attempts | ||
| CVE-2019-4392 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | ||
| CVE-2022-42447 | Cri | 0.62 | 9.6 | 0.00 | Apr 2, 2023 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. | ||
| CVE-2023-37538 | Cri | 0.60 | 9.3 | 0.00 | Oct 11, 2023 | HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | ||
| CVE-2023-37502 | Cri | 0.59 | 9.0 | 0.00 | Oct 18, 2023 | HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser. | ||
| CVE-2021-27779 | Cri | 0.59 | 9.1 | 0.01 | May 25, 2022 | VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server. | ||
| CVE-2021-27741 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2021 | " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection" |
- risk 0.64cvss 9.8epss 0.00
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which…
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.
- risk 0.64cvss 9.8epss 0.01
"HCL Digital Experience is susceptible to Server Side Request Forgery."
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard is vulnerable to excessive authorization attempts
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
- risk 0.62cvss 9.6epss 0.00
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
- risk 0.60cvss 9.3epss 0.00
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
- risk 0.59cvss 9.0epss 0.00
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
- risk 0.59cvss 9.1epss 0.01
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
- risk 0.59cvss 9.1epss 0.01
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"