VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2025-0272MedApr 3, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

  • CVE-2024-30140MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.

  • CVE-2024-30112MedJun 25, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based…

  • CVE-2023-37527MedFeb 2, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.

  • CVE-2023-50344MedJan 3, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

  • CVE-2023-28017MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the…

  • CVE-2023-37533MedNov 9, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow…

  • CVE-2023-28012MedJul 27, 2023
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • CVE-2021-27782MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

  • CVE-2021-27780MedMay 27, 2022
    risk 0.35cvss 5.3epss 0.01

    The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

  • CVE-2021-27769MedMay 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an…

  • CVE-2021-27746MedOct 21, 2021
    risk 0.35cvss 5.4epss 0.00

    "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"

  • CVE-2020-14270MedDec 22, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.

  • CVE-2020-14248MedDec 16, 2020
    risk 0.35cvss 5.3epss 0.01

    BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

  • CVE-2020-4128MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.

  • CVE-2020-4129MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and…

  • CVE-2020-4104MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in…

  • CVE-2019-4091MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "

  • CVE-2019-4090MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."

  • CVE-2020-4084MedMar 9, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2020-4082MedMar 5, 2020
    risk 0.35cvss 5.4epss 0.01

    The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security…

  • CVE-2019-4409MedOct 18, 2019
    risk 0.35cvss 5.4epss 0.01

    HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message…

  • CVE-2026-21755MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

  • CVE-2025-68833MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

  • CVE-2025-31960MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the…

  • CVE-2025-31970MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)

  • CVE-2025-31981MedApr 21, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

  • CVE-2023-37525MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

  • CVE-2025-0275MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-0274MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-31996MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.

  • CVE-2025-52616MedOct 12, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.

  • CVE-2025-31977MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

  • CVE-2025-52621MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

  • CVE-2025-52619MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.

  • CVE-2024-42213MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2024-30154MedMar 3, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2024-30150MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.

  • CVE-2024-42172MedJan 11, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can…

  • CVE-2024-30133MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

  • CVE-2024-23586MedSep 27, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

  • CVE-2024-23562MedJul 8, 2024
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.

  • CVE-2024-23588MedJul 5, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

  • CVE-2024-23540MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.01

    The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

  • CVE-2023-45703MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.00

    HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.

  • CVE-2023-28015MedMay 23, 2023
    risk 0.34cvss 5.3epss 0.00

    The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not.  The attacker could use this information to focus a…

  • CVE-2022-27551MedAug 3, 2022
    risk 0.34cvss 5.3epss 0.01

    HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.

  • CVE-2019-4325MedOct 6, 2020
    risk 0.34cvss 5.3epss 0.01

    "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

Page 6 of 13