VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2024-30117LowOct 14, 2024
    risk 0.16cvss 2.5epss 0.00

    A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

  • CVE-2023-23343LowJun 22, 2023
    risk 0.16cvss 2.4epss 0.00

    A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.

  • CVE-2025-62316LowMay 14, 2026
    risk 0.15cvss 2.3epss 0.00

    HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under…

  • CVE-2023-37521LowJan 16, 2024
    risk 0.15cvss 2.3epss 0.00

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.

  • CVE-2021-27759LowMay 6, 2022
    risk 0.15cvss 2.3epss 0.00

    This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

  • CVE-2025-52646LowMar 16, 2026
    risk 0.14cvss 2.2epss 0.00

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…

  • CVE-2025-31964LowJan 7, 2026
    risk 0.14cvss 2.2epss 0.00

    Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication…

  • CVE-2025-0250LowJul 25, 2025
    risk 0.14cvss 2.2epss 0.00

    HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.

  • CVE-2025-31962LowJan 7, 2026
    risk 0.13cvss 2.0epss 0.00

    Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

  • CVE-2025-0253LowJul 25, 2025
    risk 0.13cvss 2.0epss 0.00

    HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.

  • CVE-2024-42179LowJan 12, 2025
    risk 0.13cvss 2.0epss 0.00

    HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.

  • CVE-2023-45706LowMar 28, 2024
    risk 0.13cvss 2.0epss 0.00

    An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

  • CVE-2022-38653LowDec 19, 2022
    risk 0.13cvss 2.0epss 0.00

    In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

  • CVE-2025-52649LowMar 16, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific…

  • CVE-2025-52645LowMar 16, 2026
    risk 0.12cvss 1.9epss 0.00

    HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or…

  • CVE-2025-52636LowMar 16, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain…

  • CVE-2025-55250LowJan 19, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.

  • CVE-2023-45716LowFeb 9, 2024
    risk 0.11cvss 1.7epss 0.00

    Sametime is impacted by sensitive information passed in URL.

  • CVE-2024-42181LowJan 12, 2025
    risk 0.10cvss 1.6epss 0.00

    HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2024-42180LowJan 12, 2025
    risk 0.10cvss 1.6epss 0.00

    HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

  • CVE-2002-0370Oct 10, 2002
    risk 0.03cvss epss 0.43

    Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME,…

  • CVE-2005-2618Dec 31, 2005
    risk 0.01cvss epss 0.08

    Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a…

  • CVE-2025-62347MedJul 31, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the…

  • CVE-2026-56538LowJul 27, 2026
    risk 0.00cvss 3.5epss 0.00

    An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

  • CVE-2026-56537LowJul 27, 2026
    risk 0.00cvss 3.5epss 0.00

    HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

  • CVE-2026-56583LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

  • CVE-2026-56582LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

  • CVE-2026-56581LowJul 21, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

  • CVE-2026-56580LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

  • CVE-2026-56579LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

  • CVE-2026-56578LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

  • CVE-2026-56577LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

  • CVE-2026-56586LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

  • CVE-2026-56585LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

  • CVE-2026-56587LowJul 21, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

  • CVE-2026-56584LowJul 21, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

  • CVE-2023-37507HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

  • CVE-2023-37508MedJul 21, 2026
    risk 0.00cvss 6.1epss 0.00

    HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

  • CVE-2026-21824HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2025-59866LowJul 17, 2026
    risk 0.00cvss 3.3epss 0.00

    The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.

  • CVE-2024-42214MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.

  • CVE-2024-23578MedJul 17, 2026
    risk 0.00cvss 4.2epss 0.00

    HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).

  • CVE-2024-23577MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks,…

  • CVE-2024-23575MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.

  • CVE-2024-23574MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid…

  • CVE-2024-23573LowJul 17, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be…

  • CVE-2024-23572MedJul 17, 2026
    risk 0.00cvss 4.2epss 0.00

    HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

  • CVE-2024-23571MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this…

  • CVE-2024-23570MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing,…

  • CVE-2024-23569MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

Page 11 of 12