VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2025-62319CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently…

  • CVE-2022-44755CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44754CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44753CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44752CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44751CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44750CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2020-14245CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.

  • CVE-2020-14224CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which…

  • CVE-2020-14268CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which…

  • CVE-2020-14244CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which…

  • CVE-2020-14260CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.

  • CVE-2020-4101CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

  • CVE-2019-4393CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard is vulnerable to excessive authorization attempts

  • CVE-2019-4392CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

  • CVE-2022-42447CriApr 2, 2023
    risk 0.62cvss 9.6epss 0.00

    HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.

  • CVE-2023-37538CriOct 11, 2023
    risk 0.60cvss 9.3epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

  • CVE-2023-37502CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.00

    HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.

  • CVE-2021-27779CriMay 25, 2022
    risk 0.59cvss 9.1epss 0.01

    VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

  • CVE-2021-27741CriAug 13, 2021
    risk 0.59cvss 9.1epss 0.01

    " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

  • CVE-2024-42168HigJan 11, 2025
    risk 0.58cvss 8.9epss 0.00

    HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content.

  • CVE-2025-31951HigMay 6, 2026
    risk 0.57cvss 8.8epss 0.00

    HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

  • CVE-2026-21765HigApr 2, 2026
    risk 0.57cvss 8.8epss 0.00

    HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

  • CVE-2023-45722HigJan 3, 2024
    risk 0.57cvss 8.8epss 0.01

    HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly…

  • CVE-2020-4107HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.00

    HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

  • CVE-2020-14231HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would…

  • CVE-2020-14232HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the…

  • CVE-2024-30128HigSep 25, 2024
    risk 0.56cvss 8.6epss 0.00

    HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.

  • CVE-2022-38656HigDec 12, 2022
    risk 0.56cvss 8.6epss 0.01

    HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

  • CVE-2023-37539HigJun 6, 2024
    risk 0.55cvss 8.4epss 0.00

    The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated…

  • CVE-2026-21821HigMay 13, 2026
    risk 0.54cvss 8.3epss 0.00

    The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk…

  • CVE-2024-30151HigMay 6, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in exposure of sensitive data or…

  • CVE-2025-55262HigMar 26, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.

  • CVE-2023-50343HigJan 3, 2024
    risk 0.54cvss 8.3epss 0.00

    HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.

  • CVE-2023-37496HigAug 1, 2023
    risk 0.54cvss 8.3epss 0.00

    HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.

  • CVE-2021-27788HigMar 10, 2023
    risk 0.54cvss 8.3epss 0.01

    HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies,…

  • CVE-2022-38660HigNov 4, 2022
    risk 0.54cvss 8.3epss 0.00

    HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.  

  • CVE-2022-27546HigAug 29, 2022
    risk 0.54cvss 8.3epss 0.01

    HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a…

  • CVE-2025-59874HigJun 4, 2026
    risk 0.53cvss 8.1epss 0.00

    HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

  • CVE-2025-55261HigMar 26, 2026
    risk 0.53cvss 8.1epss 0.00

    HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data.

  • CVE-2025-0248HigNov 25, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the…

  • CVE-2025-55278HigNov 5, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to…

  • CVE-2025-52650HigOct 10, 2025
    risk 0.53cvss 8.2epss 0.00

    Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

  • CVE-2025-31965HigJul 29, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

  • CVE-2024-42193HigApr 15, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead…

  • CVE-2023-45724HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.01

    HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

  • CVE-2023-50351HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.00

    HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.

  • CVE-2023-50350HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.00

    HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

  • CVE-2023-37503HigOct 19, 2023
    risk 0.53cvss 8.1epss 0.00

    HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

  • CVE-2023-37536HigOct 11, 2023
    risk 0.53cvss 8.2epss 0.01

    An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Page 1 of 12