Vendor CVEs
HCL Software
All CVEs
622 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27760 | Med | 0.30 | 4.6 | 0.01 | May 6, 2022 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | ||
| CVE-2026-21810 | Med | 0.29 | 4.4 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary. | ||
| CVE-2025-52637 | Med | 0.29 | 4.5 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information… | ||
| CVE-2025-52626 | Med | 0.29 | 4.5 | 0.01 | Feb 3, 2026 | A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0 | ||
| CVE-2023-45707 | Med | 0.29 | 4.4 | 0.00 | Jun 8, 2024 | HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks. | ||
| CVE-2024-23560 | Med | 0.29 | 4.4 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | ||
| CVE-2021-27751 | Med | 0.29 | 4.4 | 0.00 | May 6, 2022 | HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible. | ||
| CVE-2020-4100 | Med | 0.29 | 4.4 | 0.00 | Jul 15, 2020 | "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded… | ||
| CVE-2026-21759 | Med | 0.28 | 4.3 | 0.00 | Aug 24, 2026 | HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack… | ||
| CVE-2026-21832 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||
| CVE-2026-56620 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | ||
| CVE-2025-62347 | Med | 0.28 | 4.3 | 0.00 | Jul 31, 2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the… | ||
| CVE-2025-59872 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or… | ||
| CVE-2025-52606 | Med | 0.28 | 4.3 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is… | ||
| CVE-2025-62311 | Med | 0.28 | 4.3 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions | ||
| CVE-2025-15634 | Med | 0.28 | 4.3 | 0.00 | May 9, 2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | ||
| CVE-2025-55273 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | ||
| CVE-2025-55268 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | ||
| CVE-2026-21783 | Med | 0.28 | 4.3 | 0.00 | Mar 24, 2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers… | ||
| CVE-2025-31994 | Med | 0.28 | 4.3 | 0.00 | Oct 13, 2025 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated… | ||
| CVE-2025-52620 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format. | ||
| CVE-2025-52618 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries. | ||
| CVE-2025-0279 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's… | ||
| CVE-2025-0278 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. | ||
| CVE-2025-0256 | Med | 0.28 | 4.3 | 0.00 | Mar 24, 2025 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. | ||
| CVE-2024-30143 | Med | 0.28 | 4.3 | 0.00 | Mar 13, 2025 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the… | ||
| CVE-2024-23561 | Med | 0.28 | 4.3 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. | ||
| CVE-2023-45701 | Med | 0.28 | 4.3 | 0.00 | Dec 28, 2023 | HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | ||
| CVE-2023-45700 | Med | 0.28 | 4.3 | 0.00 | Dec 21, 2023 | HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | ||
| CVE-2021-27758 | Med | 0.28 | 4.3 | 0.00 | May 6, 2022 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account. | ||
| CVE-2019-4323 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." | ||
| CVE-2026-21808 | Med | 0.27 | 4.1 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details. | ||
| CVE-2026-21753 | Med | 0.27 | 4.2 | 0.00 | Aug 25, 2026 | HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment. | ||
| CVE-2026-21761 | Med | 0.27 | 4.2 | 0.00 | Jul 17, 2026 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. | ||
| CVE-2025-55269 | Med | 0.27 | 4.2 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. | ||
| CVE-2025-52602 | Med | 0.27 | 4.2 | 0.00 | Nov 5, 2025 | HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can use that information to target… | ||
| CVE-2025-31997 | Med | 0.27 | 4.2 | 0.00 | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | ||
| CVE-2024-30146 | Med | 0.27 | 4.1 | 0.00 | Apr 30, 2025 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem. | ||
| CVE-2024-30148 | Med | 0.27 | 4.1 | 0.00 | Apr 24, 2025 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem. | ||
| CVE-2021-27773 | Med | 0.27 | 4.2 | 0.00 | May 12, 2022 | This vulnerability allows users to execute a clickjacking attack in the meeting's chat. | ||
| CVE-2026-56569 | Med | 0.26 | 4.0 | 0.00 | Jul 31, 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | ||
| CVE-2026-21785 | Med | 0.26 | 4.0 | 0.00 | May 27, 2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. | ||
| CVE-2025-31973 | Med | 0.26 | 4.0 | 0.00 | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. | ||
| CVE-2026-21767 | Med | 0.26 | 4.0 | 0.00 | Apr 2, 2026 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | ||
| CVE-2025-31969 | Med | 0.26 | 4.0 | 0.00 | Oct 12, 2025 | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking. | ||
| CVE-2024-30124 | Med | 0.26 | 4.0 | 0.00 | Oct 23, 2024 | HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously. | ||
| CVE-2023-45696 | Med | 0.26 | 4.0 | 0.00 | Feb 10, 2024 | Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser. | ||
| CVE-2023-28010 | Med | 0.26 | 4.0 | 0.00 | Sep 8, 2023 | In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. | ||
| CVE-2022-27549 | Med | 0.26 | 4.0 | 0.00 | Jul 6, 2022 | HCL Launch may store certain data for recurring activities in a plain text format. | ||
| CVE-2026-21807 | Low | 0.25 | 3.9 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. |
- risk 0.30cvss 4.6epss 0.01
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
- risk 0.29cvss 4.4epss 0.00
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
- risk 0.29cvss 4.5epss 0.00
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…
- risk 0.29cvss 4.5epss 0.01
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0
- risk 0.29cvss 4.4epss 0.00
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
- risk 0.29cvss 4.4epss 0.00
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
- risk 0.29cvss 4.4epss 0.00
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
- risk 0.29cvss 4.4epss 0.00
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded…
- risk 0.28cvss 4.3epss 0.00
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack…
- risk 0.28cvss 4.3epss 0.00
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
- risk 0.28cvss 4.3epss 0.00
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.
- risk 0.28cvss 4.3epss 0.00
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the…
- risk 0.28cvss 4.3epss 0.00
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…
- risk 0.28cvss 4.3epss 0.00
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…
- risk 0.28cvss 4.3epss 0.00
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions
- risk 0.28cvss 4.3epss 0.00
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers…
- risk 0.28cvss 4.3epss 0.00
HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated…
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
- risk 0.28cvss 4.3epss 0.00
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
- risk 0.28cvss 4.3epss 0.00
HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the…
- risk 0.28cvss 4.3epss 0.00
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
- risk 0.28cvss 4.3epss 0.00
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
- risk 0.28cvss 4.3epss 0.00
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
- risk 0.28cvss 4.3epss 0.00
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
- risk 0.28cvss 4.3epss 0.01
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
- risk 0.27cvss 4.1epss 0.00
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
- risk 0.27cvss 4.2epss 0.00
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
- risk 0.27cvss 4.2epss 0.00
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
- risk 0.27cvss 4.2epss 0.00
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.
- risk 0.27cvss 4.2epss 0.00
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can use that information to target…
- risk 0.27cvss 4.2epss 0.00
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
- risk 0.27cvss 4.1epss 0.00
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
- risk 0.27cvss 4.1epss 0.00
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
- risk 0.27cvss 4.2epss 0.00
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
- risk 0.26cvss 4.0epss 0.00
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
- risk 0.26cvss 4.0epss 0.00
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
- risk 0.26cvss 4.0epss 0.00
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
- risk 0.26cvss 4.0epss 0.00
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication.
- risk 0.26cvss 4.0epss 0.00
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
- risk 0.26cvss 4.0epss 0.00
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
- risk 0.26cvss 4.0epss 0.00
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
- risk 0.26cvss 4.0epss 0.00
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
- risk 0.26cvss 4.0epss 0.00
HCL Launch may store certain data for recurring activities in a plain text format.
- risk 0.25cvss 3.9epss 0.00
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Page 8 of 13