VYPR

Vendor CVEs

HCL Software

All CVEs

623 total · sorted by risk
  • CVE-2025-31953HigJul 24, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.

  • CVE-2025-31952HigJul 24, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

  • CVE-2023-37535HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

  • CVE-2023-37534HigApr 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

  • CVE-2024-42169HigJan 11, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should be allowed to access specific data.

  • CVE-2024-23576HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2023-50342HigJan 3, 2024
    risk 0.46cvss 7.1epss 0.00

    HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.

  • CVE-2023-37504HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the…

  • CVE-2023-28006HigJun 22, 2023
    risk 0.46cvss 7.0epss 0.00

    The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.

  • CVE-2023-28008HigApr 26, 2023
    risk 0.46cvss 7.1epss 0.01

    HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2021-27772HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.01

    Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it.…

  • CVE-2019-16188HigSep 25, 2019
    risk 0.46cvss 7.1epss 0.01

    HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in…

  • CVE-2022-42453MedDec 19, 2022
    risk 0.45cvss 6.9epss 0.00

    There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.

  • CVE-2025-31991MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

  • CVE-2025-31990MedFeb 7, 2026
    risk 0.44cvss 6.8epss 0.00

    Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate…

  • CVE-2025-62346MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.

  • CVE-2024-23589MedMay 30, 2025
    risk 0.44cvss 6.8epss 0.00

    Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs

  • CVE-2024-42170MedJan 11, 2025
    risk 0.44cvss 6.8epss 0.00

    HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

  • CVE-2024-30134MedSep 26, 2024
    risk 0.44cvss 6.7epss 0.00

    The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.

  • CVE-2024-23583MedMay 17, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

  • CVE-2021-27783MedMay 25, 2022
    risk 0.44cvss 6.8epss 0.00

    User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

  • CVE-2021-27770MedMay 12, 2022
    risk 0.44cvss 6.8epss 0.01

    The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will…

  • CVE-2021-27767MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27766MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27765MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2020-4102MedDec 2, 2020
    risk 0.44cvss 6.7epss 0.00

    HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system.

  • CVE-2020-4097MedNov 5, 2020
    risk 0.44cvss 6.8epss 0.00

    In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an…

  • CVE-2025-62299MedAug 20, 2026
    risk 0.43cvss 6.6epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.

  • CVE-2024-23584MedApr 8, 2024
    risk 0.43cvss 6.6epss 0.00

    The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

  • CVE-2023-28025MedDec 21, 2023
    risk 0.43cvss 6.6epss 0.00

    Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before…

  • CVE-2023-23342MedAug 10, 2023
    risk 0.43cvss 6.6epss 0.00

    If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 

  • CVE-2023-28014MedJul 27, 2023
    risk 0.43cvss 6.6epss 0.00

    HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

  • CVE-2021-27781MedMay 27, 2022
    risk 0.43cvss 6.6epss 0.00

    The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

  • CVE-2026-56592MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized…

  • CVE-2026-56590MedSep 18, 2026
    risk 0.42cvss 6.4epss 0.00

    HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise.

  • CVE-2026-67071MedSep 17, 2026
    risk 0.42cvss 6.5epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent…

  • CVE-2025-62342MedAug 27, 2026
    risk 0.42cvss 6.4epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.

  • CVE-2026-21836MedMay 20, 2026
    risk 0.42cvss 6.5epss 0.00

    The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable an authenticated attacker to view…

  • CVE-2025-15633MedMay 9, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate…

  • CVE-2025-55265MedMar 26, 2026
    risk 0.42cvss 6.5epss 0.00

    HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks.

  • CVE-2025-0277MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-0276MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-52632MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

  • CVE-2025-31972MedAug 28, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.

  • CVE-2024-42191MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2024-42190MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2024-30145MedApr 30, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-30152MedApr 25, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

  • CVE-2024-30147MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-42189MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

Page 3 of 13