VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2021-27760MedMay 6, 2022
    risk 0.30cvss 4.6epss 0.01

    An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.

  • CVE-2026-21810MedAug 26, 2026
    risk 0.29cvss 4.4epss 0.00

    HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.

  • CVE-2025-52637MedMar 16, 2026
    risk 0.29cvss 4.5epss 0.00

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…

  • CVE-2025-52626MedFeb 3, 2026
    risk 0.29cvss 4.5epss 0.01

    A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0

  • CVE-2023-45707MedJun 8, 2024
    risk 0.29cvss 4.4epss 0.00

    HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.

  • CVE-2024-23560MedApr 15, 2024
    risk 0.29cvss 4.4epss 0.00

    HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

  • CVE-2021-27751MedMay 6, 2022
    risk 0.29cvss 4.4epss 0.00

    HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

  • CVE-2020-4100MedJul 15, 2020
    risk 0.29cvss 4.4epss 0.00

    "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded…

  • CVE-2026-21759MedAug 24, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack…

  • CVE-2026-21832MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.

  • CVE-2026-56620MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.

  • CVE-2025-62347MedJul 31, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the…

  • CVE-2025-59872MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…

  • CVE-2025-52606MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…

  • CVE-2025-62311MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions

  • CVE-2025-15634MedMay 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.

  • CVE-2025-55273MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.

  • CVE-2025-55268MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.

  • CVE-2026-21783MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers…

  • CVE-2025-31994MedOct 13, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated…

  • CVE-2025-52620MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.

  • CVE-2025-52618MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.

  • CVE-2025-0279MedApr 3, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…

  • CVE-2025-0278MedApr 3, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.

  • CVE-2025-0256MedMar 24, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.

  • CVE-2024-30143MedMar 13, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the…

  • CVE-2024-23561MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

  • CVE-2023-45701MedDec 28, 2023
    risk 0.28cvss 4.3epss 0.00

    HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2023-45700MedDec 21, 2023
    risk 0.28cvss 4.3epss 0.00

    HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

  • CVE-2021-27758MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.00

    There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.

  • CVE-2019-4323MedJul 7, 2020
    risk 0.28cvss 4.3epss 0.01

    "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

  • CVE-2026-21808MedAug 26, 2026
    risk 0.27cvss 4.1epss 0.00

    HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.

  • CVE-2026-21753MedAug 25, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.

  • CVE-2026-21761MedJul 17, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.

  • CVE-2025-55269MedMar 26, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.

  • CVE-2025-52602MedNov 5, 2025
    risk 0.27cvss 4.2epss 0.00

    HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs).  An attacker can use that information to target…

  • CVE-2025-31997MedOct 12, 2025
    risk 0.27cvss 4.2epss 0.00

    HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.

  • CVE-2024-30146MedApr 30, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2024-30148MedApr 24, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2021-27773MedMay 12, 2022
    risk 0.27cvss 4.2epss 0.00

    This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

  • CVE-2026-56569MedJul 31, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2026-21785MedMay 27, 2026
    risk 0.26cvss 4.0epss 0.00

    A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

  • CVE-2025-31973MedMay 20, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

  • CVE-2026-21767MedApr 2, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

  • CVE-2025-31969MedOct 12, 2025
    risk 0.26cvss 4.0epss 0.00

    HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.

  • CVE-2024-30124MedOct 23, 2024
    risk 0.26cvss 4.0epss 0.00

    HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.

  • CVE-2023-45696MedFeb 10, 2024
    risk 0.26cvss 4.0epss 0.00

    Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.

  • CVE-2023-28010MedSep 8, 2023
    risk 0.26cvss 4.0epss 0.00

    In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.

  • CVE-2022-27549MedJul 6, 2022
    risk 0.26cvss 4.0epss 0.00

    HCL Launch may store certain data for recurring activities in a plain text format.

  • CVE-2026-21807LowAug 26, 2026
    risk 0.25cvss 3.9epss 0.00

    HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

Page 8 of 13