VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2023-37501HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-37500HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-37499HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.00

    A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's session and perform other attacks.

  • CVE-2023-37498HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.01

    A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate their privileges.

  • CVE-2023-37497HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.01

    The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.

  • CVE-2022-38657HigFeb 12, 2023
    risk 0.53cvss 8.2epss 0.00

    An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.

  • CVE-2021-27771HigMay 12, 2022
    risk 0.53cvss 8.2epss 0.01

    User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when…

  • CVE-2020-4125HigJul 20, 2020
    risk 0.53cvss 8.1epss 0.00

    Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.

  • CVE-2019-4391HigApr 7, 2020
    risk 0.53cvss 8.2epss 0.01

    HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

  • CVE-2023-37537HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.

  • CVE-2023-37520HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

  • CVE-2023-37519HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 

  • CVE-2022-38658HigDec 24, 2022
    risk 0.50cvss 7.7epss 0.00

    BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data…

  • CVE-2024-42210HigMar 19, 2026
    risk 0.49cvss 7.6epss 0.00

    A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data…

  • CVE-2025-52656HigOct 3, 2025
    risk 0.49cvss 7.6epss 0.00

    HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields.

  • CVE-2025-52653HigOct 3, 2025
    risk 0.49cvss 7.6epss 0.00

    HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.

  • CVE-2025-0280HigSep 3, 2025
    risk 0.49cvss 7.5epss 0.00

    A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.

  • CVE-2025-31955HigJul 24, 2025
    risk 0.49cvss 7.6epss 0.00

    HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.

  • CVE-2023-50341HigJan 3, 2024
    risk 0.49cvss 7.6epss 0.00

    HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a…

  • CVE-2023-45723HigJan 3, 2024
    risk 0.49cvss 7.6epss 0.01

    HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.

  • CVE-2022-27561HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.00

    There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

  • CVE-2022-27563HigAug 30, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

  • CVE-2021-27777HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

  • CVE-2021-27756HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

  • CVE-2021-27757HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…

  • CVE-2020-14246HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.01

    HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.

  • CVE-2020-14255HigFeb 2, 2021
    risk 0.49cvss 7.5epss 0.01

    HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.

  • CVE-2020-14274HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

  • CVE-2020-14273HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.01

    HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.

  • CVE-2020-14254HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.01

    TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

  • CVE-2020-14258HigNov 21, 2020
    risk 0.49cvss 7.5epss 0.01

    HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.

  • CVE-2020-14234HigNov 21, 2020
    risk 0.49cvss 7.5epss 0.01

    HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.

  • CVE-2020-14230HigNov 21, 2020
    risk 0.49cvss 7.5epss 0.01

    HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1…

  • CVE-2019-4326HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.01

    "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."

  • CVE-2019-4327HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

  • CVE-2025-59870HigJan 16, 2026
    risk 0.48cvss 7.4epss 0.00

    HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

  • CVE-2021-27764HigMay 6, 2022
    risk 0.48cvss 7.4epss 0.01

    Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

  • CVE-2025-55263HigMar 26, 2026
    risk 0.47cvss 7.3epss 0.00

    HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets.

  • CVE-2025-0255HigMar 24, 2025
    risk 0.47cvss 7.2epss 0.01

    HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.

  • CVE-2025-52612HigJun 4, 2026
    risk 0.46cvss 7.1epss 0.00

    HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .

  • CVE-2025-31953HigJul 24, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.

  • CVE-2025-31952HigJul 24, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

  • CVE-2023-37535HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

  • CVE-2023-37534HigApr 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

  • CVE-2024-42169HigJan 11, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should be allowed to access specific data.

  • CVE-2024-23576HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2023-50342HigJan 3, 2024
    risk 0.46cvss 7.1epss 0.00

    HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.

  • CVE-2023-37504HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the…

  • CVE-2023-28006HigJun 22, 2023
    risk 0.46cvss 7.0epss 0.00

    The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.

  • CVE-2023-28008HigApr 26, 2023
    risk 0.46cvss 7.1epss 0.01

    HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Page 2 of 12