VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2020-4092MedMay 6, 2020
    risk 0.34cvss 5.3epss 0.00

    "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…

  • CVE-2026-21848MedSep 18, 2026
    risk 0.33cvss 5.0epss 0.00

    HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.

  • CVE-2025-62306MedAug 20, 2026
    risk 0.33cvss 5.0epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.

  • CVE-2026-56567MedJul 31, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2025-62308MedMay 14, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under…

  • CVE-2025-62305MedMay 14, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.

  • CVE-2025-62329MedDec 16, 2025
    risk 0.33cvss 5.0epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

  • CVE-2025-31971MedAug 28, 2025
    risk 0.33cvss 5.1epss 0.00

    AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.

  • CVE-2023-23348MedJul 10, 2023
    risk 0.33cvss 5.1epss 0.00

    HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.

  • CVE-2022-27544MedJul 19, 2022
    risk 0.33cvss 5.0epss 0.00

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

  • CVE-2025-62327MedJan 7, 2026
    risk 0.32cvss 4.9epss 0.00

    In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.

  • CVE-2025-31988MedAug 19, 2025
    risk 0.32cvss 4.9epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.

  • CVE-2023-28023MedJul 18, 2023
    risk 0.32cvss 4.9epss 0.00

    A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 

  • CVE-2022-42445MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.

  • CVE-2022-27548MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

  • CVE-2021-27778MedJun 1, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies,…

  • CVE-2020-14221MedFeb 2, 2021
    risk 0.32cvss 4.9epss 0.01

    HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.

  • CVE-2026-21784MedAug 20, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.

  • CVE-2025-52640MedAug 13, 2026
    risk 0.31cvss 4.7epss 0.00

    HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended…

  • CVE-2026-56609MedAug 3, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…

  • CVE-2025-31976MedMay 6, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .

  • CVE-2025-62320MedMar 17, 2026
    risk 0.31cvss 4.7epss 0.00

    HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically…

  • CVE-2025-52643MedMar 16, 2026
    risk 0.31cvss 4.7epss 0.00

    HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing…

  • CVE-2025-52648MedMar 16, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

  • CVE-2025-59849MedDec 17, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

  • CVE-2025-31987MedAug 14, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

  • CVE-2024-42173MedJan 11, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.

  • CVE-2024-30141MedNov 7, 2024
    risk 0.31cvss 4.7epss 0.00

    HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.

  • CVE-2024-30149MedOct 31, 2024
    risk 0.31cvss 4.8epss 0.00

    HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

  • CVE-2024-30126MedJul 18, 2024
    risk 0.31cvss 4.7epss 0.00

    HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.

  • CVE-2023-45698MedFeb 10, 2024
    risk 0.31cvss 4.8epss 0.00

    Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.

  • CVE-2023-28020MedJul 18, 2023
    risk 0.31cvss 4.7epss 0.00

     URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.

  • CVE-2021-27762MedMay 6, 2022
    risk 0.31cvss 4.7epss 0.01

    Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

  • CVE-2021-27761MedMay 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

  • CVE-2019-4388MedDec 18, 2019
    risk 0.31cvss 4.8epss 0.01

    HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

  • CVE-2026-21760MedJul 17, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.

  • CVE-2026-21789MedMay 18, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2025-52613MedMay 6, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

  • CVE-2025-31978MedMay 6, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other…

  • CVE-2025-52628MedFeb 3, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.

  • CVE-2025-31992MedOct 12, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.

  • CVE-2025-52654MedOct 3, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

  • CVE-2022-42450MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

  • CVE-2022-42449MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

  • CVE-2022-27562MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44760MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44759MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

  • CVE-2022-42451MedOct 11, 2023
    risk 0.30cvss 4.6epss 0.00

    Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

  • CVE-2022-42452MedApr 2, 2023
    risk 0.30cvss 4.6epss 0.00

    HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

  • CVE-2022-27545MedJul 19, 2022
    risk 0.30cvss 4.6epss 0.00

    BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

Page 7 of 13