Vendor CVEs
HCL Software
All CVEs
622 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4092 | Med | 0.34 | 5.3 | 0.00 | May 6, 2020 | "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can… | ||
| CVE-2026-21848 | Med | 0.33 | 5.0 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries. | ||
| CVE-2025-62306 | Med | 0.33 | 5.0 | 0.00 | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. | ||
| CVE-2026-56567 | Med | 0.33 | 5.1 | 0.00 | Jul 31, 2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | ||
| CVE-2025-62308 | Med | 0.33 | 5.1 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under… | ||
| CVE-2025-62305 | Med | 0.33 | 5.1 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions. | ||
| CVE-2025-62329 | Med | 0.33 | 5.0 | 0.00 | Dec 16, 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions. | ||
| CVE-2025-31971 | Med | 0.33 | 5.1 | 0.00 | Aug 28, 2025 | AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information. | ||
| CVE-2023-23348 | Med | 0.33 | 5.1 | 0.00 | Jul 10, 2023 | HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. | ||
| CVE-2022-27544 | Med | 0.33 | 5.0 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may see SMTP credentials in clear text. | ||
| CVE-2025-62327 | Med | 0.32 | 4.9 | 0.00 | Jan 7, 2026 | In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries. | ||
| CVE-2025-31988 | Med | 0.32 | 4.9 | 0.00 | Aug 19, 2025 | HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access. | ||
| CVE-2023-28023 | Med | 0.32 | 4.9 | 0.00 | Jul 18, 2023 | A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). | ||
| CVE-2022-42445 | Med | 0.32 | 4.9 | 0.01 | Dec 12, 2022 | HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches. | ||
| CVE-2022-27548 | Med | 0.32 | 4.9 | 0.00 | Jul 6, 2022 | HCL Launch stores user credentials in plain clear text which can be read by a local user. | ||
| CVE-2021-27778 | Med | 0.32 | 4.9 | 0.00 | Jun 1, 2022 | HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies,… | ||
| CVE-2020-14221 | Med | 0.32 | 4.9 | 0.01 | Feb 2, 2021 | HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users. | ||
| CVE-2026-21784 | Med | 0.31 | 4.8 | 0.00 | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. | ||
| CVE-2025-52640 | Med | 0.31 | 4.7 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended… | ||
| CVE-2026-56609 | Med | 0.31 | 4.8 | 0.00 | Aug 3, 2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing… | ||
| CVE-2025-31976 | Med | 0.31 | 4.8 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. . | ||
| CVE-2025-62320 | Med | 0.31 | 4.7 | 0.00 | Mar 17, 2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically… | ||
| CVE-2025-52643 | Med | 0.31 | 4.7 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing… | ||
| CVE-2025-52648 | Med | 0.31 | 4.8 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system | ||
| CVE-2025-59849 | Med | 0.31 | 4.7 | 0.00 | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. | ||
| CVE-2025-31987 | Med | 0.31 | 4.8 | 0.00 | Aug 14, 2025 | HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion. | ||
| CVE-2024-42173 | Med | 0.31 | 4.8 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known. | ||
| CVE-2024-30141 | Med | 0.31 | 4.7 | 0.00 | Nov 7, 2024 | HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data. | ||
| CVE-2024-30149 | Med | 0.31 | 4.8 | 0.00 | Oct 31, 2024 | HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. | ||
| CVE-2024-30126 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2024 | HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge. | ||
| CVE-2023-45698 | Med | 0.31 | 4.8 | 0.00 | Feb 10, 2024 | Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks. | ||
| CVE-2023-28020 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2023 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | ||
| CVE-2021-27762 | Med | 0.31 | 4.7 | 0.01 | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses | ||
| CVE-2021-27761 | Med | 0.31 | 4.8 | 0.00 | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks | ||
| CVE-2019-4388 | Med | 0.31 | 4.8 | 0.01 | Dec 18, 2019 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | ||
| CVE-2026-21760 | Med | 0.30 | 4.6 | 0.00 | Jul 17, 2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | ||
| CVE-2026-21789 | Med | 0.30 | 4.6 | 0.00 | May 18, 2026 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | ||
| CVE-2025-52613 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access. | ||
| CVE-2025-31978 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other… | ||
| CVE-2025-52628 | Med | 0.30 | 4.6 | 0.00 | Feb 3, 2026 | HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0. | ||
| CVE-2025-31992 | Med | 0.30 | 4.6 | 0.00 | Oct 12, 2025 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. | ||
| CVE-2025-52654 | Med | 0.30 | 4.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation. | ||
| CVE-2022-42450 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. | ||
| CVE-2022-42449 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications | ||
| CVE-2022-27562 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44760 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44759 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. | ||
| CVE-2022-42451 | Med | 0.30 | 4.6 | 0.00 | Oct 11, 2023 | Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user. | ||
| CVE-2022-42452 | Med | 0.30 | 4.6 | 0.00 | Apr 2, 2023 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. | ||
| CVE-2022-27545 | Med | 0.30 | 4.6 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. |
- risk 0.34cvss 5.3epss 0.00
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…
- risk 0.33cvss 5.0epss 0.00
HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.
- risk 0.33cvss 5.0epss 0.00
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
- risk 0.33cvss 5.1epss 0.00
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
- risk 0.33cvss 5.1epss 0.00
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under…
- risk 0.33cvss 5.1epss 0.00
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.
- risk 0.33cvss 5.0epss 0.00
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
- risk 0.33cvss 5.1epss 0.00
AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.
- risk 0.33cvss 5.1epss 0.00
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
- risk 0.33cvss 5.0epss 0.00
BigFix Web Reports authorized users may see SMTP credentials in clear text.
- risk 0.32cvss 4.9epss 0.00
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.
- risk 0.32cvss 4.9epss 0.00
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
- risk 0.32cvss 4.9epss 0.00
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).
- risk 0.32cvss 4.9epss 0.01
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
- risk 0.32cvss 4.9epss 0.00
HCL Launch stores user credentials in plain clear text which can be read by a local user.
- risk 0.32cvss 4.9epss 0.00
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies,…
- risk 0.32cvss 4.9epss 0.01
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
- risk 0.31cvss 4.8epss 0.00
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
- risk 0.31cvss 4.7epss 0.00
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended…
- risk 0.31cvss 4.8epss 0.00
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…
- risk 0.31cvss 4.8epss 0.00
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .
- risk 0.31cvss 4.7epss 0.00
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically…
- risk 0.31cvss 4.7epss 0.00
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing…
- risk 0.31cvss 4.8epss 0.00
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system
- risk 0.31cvss 4.7epss 0.00
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- risk 0.31cvss 4.8epss 0.00
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
- risk 0.31cvss 4.8epss 0.00
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
- risk 0.31cvss 4.7epss 0.00
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.
- risk 0.31cvss 4.8epss 0.00
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
- risk 0.31cvss 4.7epss 0.00
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
- risk 0.31cvss 4.8epss 0.00
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
- risk 0.31cvss 4.7epss 0.00
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
- risk 0.31cvss 4.7epss 0.01
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
- risk 0.31cvss 4.8epss 0.00
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
- risk 0.31cvss 4.8epss 0.01
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
- risk 0.30cvss 4.6epss 0.00
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
- risk 0.30cvss 4.6epss 0.00
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other…
- risk 0.30cvss 4.6epss 0.00
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
- risk 0.30cvss 4.6epss 0.00
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.
- risk 0.30cvss 4.6epss 0.00
HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
- risk 0.30cvss 4.6epss 0.00
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
- risk 0.30cvss 4.6epss 0.00
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
Page 7 of 13