VYPR

Vendor CVEs

HCL Software

All CVEs

580 total · sorted by risk
  • CVE-2025-59849MedDec 17, 2025
    risk 0.31cvss 4.7epss 0.00

    Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

  • CVE-2025-31987MedAug 14, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

  • CVE-2024-42173MedJan 11, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.

  • CVE-2024-30141MedNov 7, 2024
    risk 0.31cvss 4.7epss 0.00

    HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.

  • CVE-2024-30149MedOct 31, 2024
    risk 0.31cvss 4.8epss 0.00

    HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

  • CVE-2024-30126MedJul 18, 2024
    risk 0.31cvss 4.7epss 0.00

    HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.

  • CVE-2023-45698MedFeb 10, 2024
    risk 0.31cvss 4.8epss 0.00

    Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.

  • CVE-2023-28020MedJul 18, 2023
    risk 0.31cvss 4.7epss 0.00

     URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.

  • CVE-2021-27762MedMay 6, 2022
    risk 0.31cvss 4.7epss 0.01

    Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

  • CVE-2021-27761MedMay 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

  • CVE-2019-4388MedDec 18, 2019
    risk 0.31cvss 4.8epss 0.01

    HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

  • CVE-2026-21760MedJul 17, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.

  • CVE-2026-21789MedMay 18, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2025-52613MedMay 6, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

  • CVE-2025-31978MedMay 6, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other…

  • CVE-2025-52628MedFeb 3, 2026
    risk 0.30cvss 4.6epss 0.00

    HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.

  • CVE-2025-31992MedOct 12, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.

  • CVE-2025-52654MedOct 3, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

  • CVE-2022-42450MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

  • CVE-2022-42449MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

  • CVE-2022-27562MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44760MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44759MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

  • CVE-2022-42451MedOct 11, 2023
    risk 0.30cvss 4.6epss 0.00

    Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

  • CVE-2022-42452MedApr 2, 2023
    risk 0.30cvss 4.6epss 0.00

    HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

  • CVE-2022-27545MedJul 19, 2022
    risk 0.30cvss 4.6epss 0.00

    BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

  • CVE-2021-27760MedMay 6, 2022
    risk 0.30cvss 4.6epss 0.01

    An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.

  • CVE-2025-52637MedMar 16, 2026
    risk 0.29cvss 4.5epss 0.00

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…

  • CVE-2025-52626MedFeb 3, 2026
    risk 0.29cvss 4.5epss 0.01

    A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0

  • CVE-2023-45707MedJun 8, 2024
    risk 0.29cvss 4.4epss 0.00

    HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.

  • CVE-2024-23560MedApr 15, 2024
    risk 0.29cvss 4.4epss 0.00

    HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

  • CVE-2020-4100MedJul 15, 2020
    risk 0.29cvss 4.4epss 0.00

    "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded…

  • CVE-2026-21832MedAug 13, 2026
    risk 0.28cvss 4.3epss

    HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.

  • CVE-2026-56620MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.

  • CVE-2025-59872MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…

  • CVE-2025-52606MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…

  • CVE-2025-62311MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions

  • CVE-2025-15634MedMay 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.

  • CVE-2025-55273MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.

  • CVE-2025-55268MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.

  • CVE-2026-21783MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers…

  • CVE-2025-31994MedOct 13, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated…

  • CVE-2025-52620MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.

  • CVE-2025-52618MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.

  • CVE-2025-0279MedApr 3, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…

  • CVE-2025-0278MedApr 3, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.

  • CVE-2025-0256MedMar 24, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.

  • CVE-2024-30143MedMar 13, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the…

  • CVE-2024-23561MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

  • CVE-2023-45701MedDec 28, 2023
    risk 0.28cvss 4.3epss 0.00

    HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

Page 7 of 12