VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2026-56538LowJul 27, 2026
    risk 0.23cvss 3.5epss 0.00

    An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

  • CVE-2026-56537LowJul 27, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

  • CVE-2025-15619LowJun 23, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

  • CVE-2025-31959LowMay 6, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

  • CVE-2025-55270LowMar 26, 2026
    risk 0.23cvss 3.5epss 0.01

    HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.

  • CVE-2025-52603LowFeb 20, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.

  • CVE-2025-55249LowJan 19, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.

  • CVE-2025-52639LowNov 18, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.

  • CVE-2025-31995LowOct 13, 2025
    risk 0.23cvss 3.5epss 0.01

    HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.

  • CVE-2025-52615LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.

  • CVE-2025-52614LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.

  • CVE-2025-31998LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.

  • CVE-2025-31993LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server.

  • CVE-2025-52658LowOct 3, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.

  • CVE-2024-42209LowJul 17, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.

  • CVE-2024-42208LowApr 4, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

  • CVE-2024-30106LowOct 28, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.

  • CVE-2023-50355LowOct 23, 2024
    risk 0.23cvss 3.6epss 0.00

    HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

  • CVE-2024-30118LowOct 9, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.

  • CVE-2023-37541LowJun 25, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2024-30107LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

  • CVE-2024-23557LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.

  • CVE-2023-45715LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    The console may experience a service interruption when processing file names with invalid characters.

  • CVE-2023-45705LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

  • CVE-2023-28022LowDec 15, 2023
    risk 0.23cvss 3.5epss 0.01

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

  • CVE-2023-37511LowAug 11, 2023
    risk 0.23cvss 3.5epss 0.00

    If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.

  • CVE-2025-62315LowAug 13, 2026
    risk 0.22cvss 3.4epss 0.00

    HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.

  • CVE-2025-62338LowJun 4, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized access and may lead to information exposure.

  • CVE-2025-52642LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information…

  • CVE-2026-21791LowMar 10, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL

  • CVE-2026-21786LowMar 5, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

  • CVE-2025-0249LowJul 25, 2025
    risk 0.21cvss 3.3epss 0.00

    HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to access sensitive data without authorization.

  • CVE-2023-37517LowApr 30, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

  • CVE-2024-30127LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

  • CVE-2023-37516LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits user directory information to be cached.

  • CVE-2024-30135LowJun 28, 2024
    risk 0.21cvss 3.3epss 0.00

    HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

  • CVE-2024-30111LowJun 28, 2024
    risk 0.21cvss 3.3epss 0.00

    HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially…

  • CVE-2023-37531LowFeb 29, 2024
    risk 0.21cvss 3.3epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.

  • CVE-2023-37513LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

  • CVE-2023-37512LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

  • CVE-2026-21806LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid…

  • CVE-2026-56597LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify…

  • CVE-2026-56595LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected…

  • CVE-2026-21827LowAug 31, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

  • CVE-2025-62343LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.

  • CVE-2026-21764LowJul 17, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

  • CVE-2025-62340LowJun 17, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

  • CVE-2025-52611LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object…

  • CVE-2025-52608LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

  • CVE-2024-42206LowJun 2, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iReflection Third party vulnerable and outdated components issue was detected in the web application

Page 10 of 13