VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2026-21809LowAug 26, 2026
    risk 0.25cvss 3.9epss 0.00

    HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.

  • CVE-2025-31974LowMay 6, 2026
    risk 0.25cvss 3.9epss 0.00

    HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized…

  • CVE-2024-23563LowFeb 12, 2025
    risk 0.25cvss 3.9epss 0.00

    HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

  • CVE-2024-30142LowNov 7, 2024
    risk 0.25cvss 3.8epss 0.00

    HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.

  • CVE-2023-37540LowFeb 23, 2024
    risk 0.25cvss 3.9epss 0.00

    Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.

  • CVE-2023-45718LowFeb 9, 2024
    risk 0.25cvss 3.9epss 0.00

    Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

  • CVE-2021-27785LowJul 30, 2022
    risk 0.25cvss 3.9epss 0.00

    HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

  • CVE-2020-14264LowOct 25, 2021
    risk 0.25cvss 3.9epss 0.00

    "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

  • CVE-2020-14263LowOct 21, 2021
    risk 0.25cvss 3.9epss 0.00

    "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

  • CVE-2025-62341LowAug 26, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.

  • CVE-2026-21758LowAug 25, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.

  • CVE-2025-62318LowAug 13, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.

  • CVE-2026-56608LowAug 3, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.

  • CVE-2026-56571LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.

  • CVE-2026-56570LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames…

  • CVE-2026-56568LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters,…

  • CVE-2026-21762LowJul 17, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.

  • CVE-2025-52609LowJun 4, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.

  • CVE-2025-31985LowMay 20, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed…

  • CVE-2025-31984LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed…

  • CVE-2025-31983LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information.

  • CVE-2025-31982LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

  • CVE-2025-59852LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

  • CVE-2025-59851LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to gain unauthorized access or…

  • CVE-2025-31958LowApr 21, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between…

  • CVE-2025-55275LowMar 26, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

  • CVE-2025-62328LowMar 11, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.

  • CVE-2025-52631LowFeb 3, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.

  • CVE-2025-52623LowFeb 3, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access.…

  • CVE-2025-52629LowFeb 3, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.

  • CVE-2025-55254LowDec 17, 2025
    risk 0.24cvss 3.7epss 0.00

    Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.

  • CVE-2025-52635LowOct 10, 2025
    risk 0.24cvss 3.7epss 0.00

    A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

  • CVE-2025-52625LowOct 10, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.

  • CVE-2025-52634LowOct 10, 2025
    risk 0.24cvss 3.7epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

  • CVE-2025-52630LowOct 10, 2025
    risk 0.24cvss 3.7epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

  • CVE-2025-31961LowAug 15, 2025
    risk 0.24cvss 3.7epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2024-30114LowApr 24, 2025
    risk 0.24cvss 3.7epss 0.00

    Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

  • CVE-2024-42174LowJan 11, 2025
    risk 0.24cvss 3.7epss 0.00

    HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.

  • CVE-2024-42188LowNov 14, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

  • CVE-2024-30132LowOct 1, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.

  • CVE-2024-30130LowJul 19, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.

  • CVE-2024-30110LowJun 28, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.

  • CVE-2024-30109LowJun 28, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.

  • CVE-2024-30119LowJun 14, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.

  • CVE-2023-50347LowApr 10, 2024
    risk 0.24cvss 3.7epss 0.01

    HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.

  • CVE-2023-50345LowJan 3, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.

  • CVE-2025-52657LowSep 7, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

  • CVE-2025-52652LowSep 7, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.

  • CVE-2025-52651LowSep 7, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

  • CVE-2026-56547LowAug 26, 2026
    risk 0.23cvss 3.5epss 0.00

    The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them.  The values cannot be changed later on, so the Apple profile generation page asks for those…

Page 9 of 13