VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2020-4084MedMar 9, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2020-4082MedMar 5, 2020
    risk 0.35cvss 5.4epss 0.01

    The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security…

  • CVE-2019-4409MedOct 18, 2019
    risk 0.35cvss 5.4epss 0.01

    HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message…

  • CVE-2025-31960MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the…

  • CVE-2025-31970MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)

  • CVE-2025-31981MedApr 21, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

  • CVE-2023-37525MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

  • CVE-2025-0275MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-0274MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-31996MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.

  • CVE-2025-52616MedOct 12, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.

  • CVE-2025-31977MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

  • CVE-2025-52621MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

  • CVE-2025-52619MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.

  • CVE-2024-42213MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2024-30154MedMar 3, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2024-30150MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.

  • CVE-2024-42172MedJan 11, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can…

  • CVE-2024-30133MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

  • CVE-2024-23586MedSep 27, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

  • CVE-2024-23562MedJul 8, 2024
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.

  • CVE-2024-23588MedJul 5, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

  • CVE-2024-23540MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.01

    The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

  • CVE-2023-45703MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.00

    HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.

  • CVE-2023-28015MedMay 23, 2023
    risk 0.34cvss 5.3epss 0.00

    The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not.  The attacker could use this information to focus a…

  • CVE-2022-27551MedAug 3, 2022
    risk 0.34cvss 5.3epss 0.01

    HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.

  • CVE-2019-4325MedOct 6, 2020
    risk 0.34cvss 5.3epss 0.01

    "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

  • CVE-2020-4092MedMay 6, 2020
    risk 0.34cvss 5.3epss 0.00

    "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…

  • CVE-2026-56567MedJul 31, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2025-62308MedMay 14, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under…

  • CVE-2025-62305MedMay 14, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.

  • CVE-2025-62329MedDec 16, 2025
    risk 0.33cvss 5.0epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

  • CVE-2025-31971MedAug 28, 2025
    risk 0.33cvss 5.1epss 0.00

    AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.

  • CVE-2023-23348MedJul 10, 2023
    risk 0.33cvss 5.1epss 0.00

    HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.

  • CVE-2022-27544MedJul 19, 2022
    risk 0.33cvss 5.0epss 0.00

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

  • CVE-2025-62327MedJan 7, 2026
    risk 0.32cvss 4.9epss 0.00

    In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.

  • CVE-2025-31988MedAug 19, 2025
    risk 0.32cvss 4.9epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.

  • CVE-2023-28023MedJul 18, 2023
    risk 0.32cvss 4.9epss 0.00

    A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 

  • CVE-2022-42445MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.

  • CVE-2022-27548MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

  • CVE-2021-27778MedJun 1, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies,…

  • CVE-2020-14221MedFeb 2, 2021
    risk 0.32cvss 4.9epss 0.01

    HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.

  • CVE-2025-52640MedAug 13, 2026
    risk 0.31cvss 4.7epss 0.00

    HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended…

  • CVE-2026-56609MedAug 3, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…

  • CVE-2025-31976MedMay 6, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .

  • CVE-2025-62320MedMar 17, 2026
    risk 0.31cvss 4.7epss 0.00

    HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically…

  • CVE-2025-52643MedMar 16, 2026
    risk 0.31cvss 4.7epss 0.00

    HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing…

  • CVE-2025-52648MedMar 16, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

Page 6 of 12