Vendor CVEs
HCL Software
All CVEs
622 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23580 | Med | 0.42 | 6.5 | 0.00 | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values. | ||
| CVE-2024-23579 | Med | 0.42 | 6.5 | 0.00 | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values. | ||
| CVE-2023-37526 | Med | 0.42 | 6.5 | 0.00 | May 14, 2024 | HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning… | ||
| CVE-2023-37528 | Med | 0.42 | 6.5 | 0.00 | Feb 3, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report. | ||
| CVE-2023-37518 | Med | 0.42 | 6.4 | 0.00 | Jan 30, 2024 | HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user. | ||
| CVE-2022-44758 | Med | 0.42 | 6.5 | 0.00 | Oct 11, 2023 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | ||
| CVE-2022-44757 | Med | 0.42 | 6.5 | 0.00 | Oct 11, 2023 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | ||
| CVE-2023-23347 | Med | 0.42 | 6.4 | 0.00 | Aug 9, 2023 | HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||
| CVE-2023-23346 | Med | 0.42 | 6.4 | 0.00 | Aug 9, 2023 | HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||
| CVE-2023-28013 | Med | 0.42 | 6.5 | 0.00 | Jul 26, 2023 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's… | ||
| CVE-2023-28009 | Med | 0.42 | 6.5 | 0.01 | Apr 26, 2023 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||
| CVE-2022-44756 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. | ||
| CVE-2022-42454 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access. | ||
| CVE-2022-38655 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | ||
| CVE-2022-42446 | Med | 0.42 | 6.5 | 0.00 | Dec 12, 2022 | Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users. | ||
| CVE-2020-14247 | Med | 0.42 | 6.5 | 0.01 | Feb 4, 2021 | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID. | ||
| CVE-2020-14225 | Med | 0.42 | 6.5 | 0.01 | Dec 21, 2020 | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing… | ||
| CVE-2020-4127 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2020 | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions… | ||
| CVE-2020-4089 | Med | 0.42 | 6.5 | 0.01 | Jun 26, 2020 | HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and… | ||
| CVE-2020-4085 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user." | ||
| CVE-2026-21822 | Med | 0.41 | 6.3 | 0.00 | Sep 18, 2026 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure… | ||
| CVE-2026-21768 | Med | 0.41 | 6.3 | 0.00 | Jun 19, 2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations. | ||
| CVE-2026-21790 | Med | 0.41 | 6.3 | 0.00 | Mar 24, 2026 | HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks. | ||
| CVE-2024-30115 | Med | 0.41 | 6.3 | 0.00 | Apr 30, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | ||
| CVE-2024-30113 | Med | 0.41 | 6.3 | 0.00 | Apr 24, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | ||
| CVE-2025-0257 | Med | 0.41 | 6.3 | 0.00 | Apr 2, 2025 | HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. | ||
| CVE-2024-23558 | Med | 0.41 | 6.3 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | ||
| CVE-2021-27768 | Med | 0.41 | 6.3 | 0.00 | May 12, 2022 | Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in… | ||
| CVE-2026-21826 | Med | 0.40 | 6.1 | 0.00 | Jun 5, 2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | ||
| CVE-2025-62326 | Med | 0.40 | 6.1 | 0.00 | Feb 20, 2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. | ||
| CVE-2025-52647 | Med | 0.40 | 6.1 | 0.00 | Oct 10, 2025 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks. | ||
| CVE-2024-42196 | Med | 0.40 | 6.2 | 0.00 | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs. | ||
| CVE-2024-30125 | Med | 0.40 | 6.2 | 0.00 | Jul 18, 2024 | HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die. | ||
| CVE-2024-23559 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. | ||
| CVE-2024-23550 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2024 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. | ||
| CVE-2023-45702 | Med | 0.40 | 6.2 | 0.00 | Dec 28, 2023 | An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.. | ||
| CVE-2022-38662 | Med | 0.40 | 6.1 | 0.00 | Dec 19, 2022 | In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. | ||
| CVE-2022-38661 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2022 | HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash. | ||
| CVE-2022-27547 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2022 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | ||
| CVE-2020-4081 | Med | 0.40 | 6.1 | 0.01 | Feb 2, 2021 | In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). | ||
| CVE-2020-14271 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2020 | HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web… | ||
| CVE-2020-4080 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2020 | HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser… | ||
| CVE-2020-14240 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting… | ||
| CVE-2020-14222 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | ||
| CVE-2020-14223 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack. | ||
| CVE-2019-4324 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." | ||
| CVE-2017-1659 | Med | 0.40 | 6.1 | 0.01 | Jul 1, 2020 | "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials." | ||
| CVE-2019-4209 | Med | 0.40 | 6.1 | 0.01 | May 1, 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. | ||
| CVE-2022-38659 | Med | 0.39 | 6.0 | 0.00 | Dec 19, 2022 | In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent. | ||
| CVE-2022-27560 | Med | 0.39 | 6.0 | 0.00 | Aug 30, 2022 | HCL VersionVault Express exposes administrator credentials. |
- risk 0.42cvss 6.5epss 0.00
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
- risk 0.42cvss 6.5epss 0.00
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
- risk 0.42cvss 6.5epss 0.00
HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning…
- risk 0.42cvss 6.5epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
- risk 0.42cvss 6.4epss 0.00
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
- risk 0.42cvss 6.5epss 0.00
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
- risk 0.42cvss 6.5epss 0.00
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
- risk 0.42cvss 6.4epss 0.00
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- risk 0.42cvss 6.4epss 0.00
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- risk 0.42cvss 6.5epss 0.00
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's…
- risk 0.42cvss 6.5epss 0.01
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- risk 0.42cvss 6.4epss 0.00
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access.
- risk 0.42cvss 6.4epss 0.00
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access.
- risk 0.42cvss 6.4epss 0.00
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
- risk 0.42cvss 6.5epss 0.00
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.
- risk 0.42cvss 6.5epss 0.01
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
- risk 0.42cvss 6.5epss 0.01
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing…
- risk 0.42cvss 6.5epss 0.00
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…
- risk 0.42cvss 6.5epss 0.01
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and…
- risk 0.42cvss 6.5epss 0.01
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
- risk 0.41cvss 6.3epss 0.00
HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure…
- risk 0.41cvss 6.3epss 0.00
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
- risk 0.41cvss 6.3epss 0.00
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
- risk 0.41cvss 6.3epss 0.00
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
- risk 0.41cvss 6.3epss 0.00
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
- risk 0.41cvss 6.3epss 0.00
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
- risk 0.41cvss 6.3epss 0.00
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- risk 0.41cvss 6.3epss 0.00
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in…
- risk 0.40cvss 6.1epss 0.00
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
- risk 0.40cvss 6.1epss 0.00
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
- risk 0.40cvss 6.1epss 0.00
The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.
- risk 0.40cvss 6.2epss 0.00
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
- risk 0.40cvss 6.2epss 0.00
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
- risk 0.40cvss 6.1epss 0.00
HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
- risk 0.40cvss 6.2epss 0.00
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
- risk 0.40cvss 6.2epss 0.00
An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
- risk 0.40cvss 6.1epss 0.00
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
- risk 0.40cvss 6.2epss 0.00
HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.
- risk 0.40cvss 6.1epss 0.01
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
- risk 0.40cvss 6.1epss 0.01
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web…
- risk 0.40cvss 6.1epss 0.01
HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser…
- risk 0.40cvss 6.1epss 0.01
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting…
- risk 0.40cvss 6.1epss 0.01
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
- risk 0.40cvss 6.1epss 0.01
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
- risk 0.40cvss 6.1epss 0.01
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
- risk 0.40cvss 6.1epss 0.01
"HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
- risk 0.40cvss 6.1epss 0.01
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
- risk 0.39cvss 6.0epss 0.00
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
- risk 0.39cvss 6.0epss 0.00
HCL VersionVault Express exposes administrator credentials.
Page 4 of 13