VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2017-1712MedJul 1, 2020
    risk 0.38cvss 5.9epss 0.01

    "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…

  • CVE-2025-55267MedMar 26, 2026
    risk 0.37cvss 5.7epss 0.00

    HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.

  • CVE-2024-23554MedMay 18, 2024
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

  • CVE-2025-62314MedAug 13, 2026
    risk 0.36cvss 5.6epss

    HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under…

  • CVE-2025-55264MedMar 26, 2026
    risk 0.36cvss 5.5epss 0.00

    HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.

  • CVE-2025-52638MedMar 16, 2026
    risk 0.36cvss 5.6epss 0.00

    HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning…

  • CVE-2025-52627MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.

  • CVE-2024-42197MedDec 11, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.

  • CVE-2025-51733MedNov 28, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-42192MedOct 16, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.

  • CVE-2025-0273MedMar 27, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.

  • CVE-2024-30155MedMar 26, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

  • CVE-2024-42207MedFeb 5, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

  • CVE-2023-28018MedFeb 12, 2024
    risk 0.36cvss 5.5epss 0.00

    HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

  • CVE-2023-37523MedJan 16, 2024
    risk 0.36cvss 5.6epss 0.00

    Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.

  • CVE-2023-37522MedJan 16, 2024
    risk 0.36cvss 5.6epss 0.00

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.

  • CVE-2023-28019MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.

  • CVE-2022-38654MedNov 4, 2022
    risk 0.36cvss 5.5epss 0.00

    HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a…

  • CVE-2021-27755MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android potential path traversal vulnerability when using File class"

  • CVE-2021-27753MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android PathTraversal Vulnerability"

  • CVE-2020-4083MedMar 5, 2020
    risk 0.36cvss 5.5epss 0.00

    HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

  • CVE-2026-56619MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.

  • CVE-2026-21766MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications…

  • CVE-2025-62313MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

  • CVE-2025-62310MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.

  • CVE-2026-21788MedMar 19, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based…

  • CVE-2025-52622MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting…

  • CVE-2025-31954MedNov 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…

  • CVE-2025-52624MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects…

  • CVE-2025-31979MedAug 28, 2025
    risk 0.35cvss 5.4epss 0.00

    A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts,…

  • CVE-2024-42212MedMay 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

  • CVE-2024-42200MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

  • CVE-2025-0272MedApr 3, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

  • CVE-2024-30140MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.

  • CVE-2024-30112MedJun 25, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based…

  • CVE-2023-37527MedFeb 2, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.

  • CVE-2023-50344MedJan 3, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

  • CVE-2023-28017MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the…

  • CVE-2023-37533MedNov 9, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow…

  • CVE-2023-28012MedJul 27, 2023
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • CVE-2021-27782MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

  • CVE-2021-27780MedMay 27, 2022
    risk 0.35cvss 5.3epss 0.01

    The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

  • CVE-2021-27769MedMay 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an…

  • CVE-2021-27746MedOct 21, 2021
    risk 0.35cvss 5.4epss 0.00

    "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"

  • CVE-2020-14270MedDec 22, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.

  • CVE-2020-4128MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.

  • CVE-2020-4129MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and…

  • CVE-2020-4104MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in…

  • CVE-2019-4091MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "

  • CVE-2019-4090MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."

Page 5 of 12