Vendor CVEs
HCL Software
All CVEs
580 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59849 | Med | 0.31 | 4.7 | 0.00 | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. | ||
| CVE-2025-31987 | Med | 0.31 | 4.8 | 0.00 | Aug 14, 2025 | HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion. | ||
| CVE-2024-42173 | Med | 0.31 | 4.8 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known. | ||
| CVE-2024-30141 | Med | 0.31 | 4.7 | 0.00 | Nov 7, 2024 | HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data. | ||
| CVE-2024-30149 | Med | 0.31 | 4.8 | 0.00 | Oct 31, 2024 | HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. | ||
| CVE-2024-30126 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2024 | HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge. | ||
| CVE-2023-45698 | Med | 0.31 | 4.8 | 0.00 | Feb 10, 2024 | Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks. | ||
| CVE-2023-28020 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2023 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | ||
| CVE-2021-27762 | Med | 0.31 | 4.7 | 0.01 | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses | ||
| CVE-2021-27761 | Med | 0.31 | 4.8 | 0.00 | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks | ||
| CVE-2019-4388 | Med | 0.31 | 4.8 | 0.01 | Dec 18, 2019 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | ||
| CVE-2026-21760 | Med | 0.30 | 4.6 | 0.00 | Jul 17, 2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | ||
| CVE-2026-21789 | Med | 0.30 | 4.6 | 0.00 | May 18, 2026 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | ||
| CVE-2025-52613 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access. | ||
| CVE-2025-31978 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other… | ||
| CVE-2025-52628 | Med | 0.30 | 4.6 | 0.00 | Feb 3, 2026 | HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0. | ||
| CVE-2025-31992 | Med | 0.30 | 4.6 | 0.00 | Oct 12, 2025 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. | ||
| CVE-2025-52654 | Med | 0.30 | 4.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation. | ||
| CVE-2022-42450 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. | ||
| CVE-2022-42449 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications | ||
| CVE-2022-27562 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44760 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44759 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. | ||
| CVE-2022-42451 | Med | 0.30 | 4.6 | 0.00 | Oct 11, 2023 | Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user. | ||
| CVE-2022-42452 | Med | 0.30 | 4.6 | 0.00 | Apr 2, 2023 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. | ||
| CVE-2022-27545 | Med | 0.30 | 4.6 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. | ||
| CVE-2021-27760 | Med | 0.30 | 4.6 | 0.01 | May 6, 2022 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | ||
| CVE-2025-52637 | Med | 0.29 | 4.5 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information… | ||
| CVE-2025-52626 | Med | 0.29 | 4.5 | 0.01 | Feb 3, 2026 | A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0 | ||
| CVE-2023-45707 | Med | 0.29 | 4.4 | 0.00 | Jun 8, 2024 | HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks. | ||
| CVE-2024-23560 | Med | 0.29 | 4.4 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | ||
| CVE-2020-4100 | Med | 0.29 | 4.4 | 0.00 | Jul 15, 2020 | "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded… | ||
| CVE-2026-21832 | Med | 0.28 | 4.3 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||
| CVE-2026-56620 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | ||
| CVE-2025-59872 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or… | ||
| CVE-2025-52606 | Med | 0.28 | 4.3 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is… | ||
| CVE-2025-62311 | Med | 0.28 | 4.3 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions | ||
| CVE-2025-15634 | Med | 0.28 | 4.3 | 0.00 | May 9, 2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | ||
| CVE-2025-55273 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | ||
| CVE-2025-55268 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | ||
| CVE-2026-21783 | Med | 0.28 | 4.3 | 0.00 | Mar 24, 2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers… | ||
| CVE-2025-31994 | Med | 0.28 | 4.3 | 0.00 | Oct 13, 2025 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated… | ||
| CVE-2025-52620 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format. | ||
| CVE-2025-52618 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries. | ||
| CVE-2025-0279 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's… | ||
| CVE-2025-0278 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. | ||
| CVE-2025-0256 | Med | 0.28 | 4.3 | 0.00 | Mar 24, 2025 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. | ||
| CVE-2024-30143 | Med | 0.28 | 4.3 | 0.00 | Mar 13, 2025 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the… | ||
| CVE-2024-23561 | Med | 0.28 | 4.3 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. | ||
| CVE-2023-45701 | Med | 0.28 | 4.3 | 0.00 | Dec 28, 2023 | HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
- risk 0.31cvss 4.7epss 0.00
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- risk 0.31cvss 4.8epss 0.00
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
- risk 0.31cvss 4.8epss 0.00
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
- risk 0.31cvss 4.7epss 0.00
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.
- risk 0.31cvss 4.8epss 0.00
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
- risk 0.31cvss 4.7epss 0.00
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
- risk 0.31cvss 4.8epss 0.00
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
- risk 0.31cvss 4.7epss 0.00
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
- risk 0.31cvss 4.7epss 0.01
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
- risk 0.31cvss 4.8epss 0.00
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
- risk 0.31cvss 4.8epss 0.01
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
- risk 0.30cvss 4.6epss 0.00
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
- risk 0.30cvss 4.6epss 0.00
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other…
- risk 0.30cvss 4.6epss 0.00
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
- risk 0.30cvss 4.6epss 0.00
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.
- risk 0.30cvss 4.6epss 0.00
HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
- risk 0.30cvss 4.6epss 0.00
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
- risk 0.30cvss 4.6epss 0.00
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
- risk 0.30cvss 4.6epss 0.01
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
- risk 0.29cvss 4.5epss 0.00
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…
- risk 0.29cvss 4.5epss 0.01
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0
- risk 0.29cvss 4.4epss 0.00
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
- risk 0.29cvss 4.4epss 0.00
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
- risk 0.29cvss 4.4epss 0.00
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded…
- risk 0.28cvss 4.3epss —
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
- risk 0.28cvss 4.3epss 0.00
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.
- risk 0.28cvss 4.3epss 0.00
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…
- risk 0.28cvss 4.3epss 0.00
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…
- risk 0.28cvss 4.3epss 0.00
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions
- risk 0.28cvss 4.3epss 0.00
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers…
- risk 0.28cvss 4.3epss 0.00
HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated…
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
- risk 0.28cvss 4.3epss 0.00
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
- risk 0.28cvss 4.3epss 0.00
HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the…
- risk 0.28cvss 4.3epss 0.00
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
- risk 0.28cvss 4.3epss 0.00
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Page 7 of 12