VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2022-42446MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

  • CVE-2020-14247MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.01

    HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.

  • CVE-2020-14225MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.01

    HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing…

  • CVE-2020-4127MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…

  • CVE-2020-4089MedJun 26, 2020
    risk 0.42cvss 6.5epss 0.01

    HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and…

  • CVE-2020-4085MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

  • CVE-2026-21768MedJun 19, 2026
    risk 0.41cvss 6.3epss 0.00

    The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

  • CVE-2026-21790MedMar 24, 2026
    risk 0.41cvss 6.3epss 0.00

    HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.

  • CVE-2024-30115MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2024-30113MedApr 24, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2025-0257MedApr 2, 2025
    risk 0.41cvss 6.3epss 0.00

    HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.

  • CVE-2024-23558MedApr 15, 2024
    risk 0.41cvss 6.3epss 0.00

    HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2021-27768MedMay 12, 2022
    risk 0.41cvss 6.3epss 0.00

    Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in…

  • CVE-2026-21826MedJun 5, 2026
    risk 0.40cvss 6.1epss 0.00

    HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

  • CVE-2025-62326MedFeb 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.

  • CVE-2025-52647MedOct 10, 2025
    risk 0.40cvss 6.1epss 0.00

    The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

  • CVE-2024-42196MedDec 6, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

  • CVE-2024-30125MedJul 18, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

  • CVE-2024-23559MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

  • CVE-2024-23550MedFeb 3, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

  • CVE-2023-45702MedDec 28, 2023
    risk 0.40cvss 6.2epss 0.00

    An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..

  • CVE-2022-38662MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.00

     In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

  • CVE-2022-38661MedDec 12, 2022
    risk 0.40cvss 6.2epss 0.00

    HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.

  • CVE-2022-27547MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.00

    HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.

  • CVE-2020-4081MedFeb 2, 2021
    risk 0.40cvss 6.1epss 0.01

    In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).

  • CVE-2020-14271MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web…

  • CVE-2020-4080MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser…

  • CVE-2020-14240MedNov 5, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting…

  • CVE-2020-14222MedNov 5, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

  • CVE-2020-14223MedOct 1, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.

  • CVE-2019-4324MedJul 7, 2020
    risk 0.40cvss 6.1epss 0.01

    "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."

  • CVE-2017-1659MedJul 1, 2020
    risk 0.40cvss 6.1epss 0.01

    "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."

  • CVE-2019-4209MedMay 1, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

  • CVE-2022-38659MedDec 19, 2022
    risk 0.39cvss 6.0epss 0.00

    In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

  • CVE-2022-27560MedAug 30, 2022
    risk 0.39cvss 6.0epss 0.00

    HCL VersionVault Express exposes administrator credentials.

  • CVE-2020-4095MedJul 16, 2020
    risk 0.39cvss 6.0epss 0.00

    "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…

  • CVE-2025-55266MedMar 26, 2026
    risk 0.38cvss 5.9epss 0.00

    HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

  • CVE-2025-52644MedMar 16, 2026
    risk 0.38cvss 5.8epss 0.00

    HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation…

  • CVE-2025-59873MedFeb 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site…

  • CVE-2025-62330MedDec 16, 2025
    risk 0.38cvss 5.9epss 0.00

    HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related…

  • CVE-2024-30122MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

  • CVE-2024-23556MedMay 18, 2024
    risk 0.38cvss 5.9epss 0.00

    SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

  • CVE-2023-37495MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…

  • CVE-2023-50349MedFeb 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.

  • CVE-2023-37532MedOct 23, 2023
    risk 0.38cvss 5.8epss 0.01

    HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

  • CVE-2023-28021MedJul 18, 2023
    risk 0.38cvss 5.9epss 0.00

    The BigFix WebUI uses weak cipher suites.

  • CVE-2020-4099MedNov 1, 2022
    risk 0.38cvss 5.9epss 0.00

    The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

  • CVE-2021-27784MedOct 31, 2022
    risk 0.38cvss 5.9epss 0.00

    The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

  • CVE-2022-27558MedAug 29, 2022
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

  • CVE-2020-4126MedDec 1, 2020
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…

Page 4 of 12