Vendor CVEs
HCL Software
All CVEs
580 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-52630 | Low | 0.24 | 3.7 | 0.00 | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0. | ||
| CVE-2025-31961 | Low | 0.24 | 3.7 | 0.00 | Aug 15, 2025 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | ||
| CVE-2024-30114 | Low | 0.24 | 3.7 | 0.00 | Apr 24, 2025 | Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. | ||
| CVE-2024-42174 | Low | 0.24 | 3.7 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames. | ||
| CVE-2024-42188 | Low | 0.24 | 3.7 | 0.00 | Nov 14, 2024 | HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios. | ||
| CVE-2024-30132 | Low | 0.24 | 3.7 | 0.00 | Oct 1, 2024 | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors. | ||
| CVE-2024-30130 | Low | 0.24 | 3.7 | 0.00 | Jul 19, 2024 | HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information. | ||
| CVE-2024-30110 | Low | 0.24 | 3.7 | 0.00 | Jun 28, 2024 | HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways. | ||
| CVE-2024-30109 | Low | 0.24 | 3.7 | 0.00 | Jun 28, 2024 | HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended. | ||
| CVE-2024-30119 | Low | 0.24 | 3.7 | 0.00 | Jun 14, 2024 | HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection. | ||
| CVE-2023-50347 | Low | 0.24 | 3.7 | 0.01 | Apr 10, 2024 | HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration. | ||
| CVE-2023-50345 | Low | 0.24 | 3.7 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats. | ||
| CVE-2025-15619 | Low | 0.23 | 3.5 | 0.00 | Jun 23, 2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario. | ||
| CVE-2025-31959 | Low | 0.23 | 3.5 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. . | ||
| CVE-2025-55270 | Low | 0.23 | 3.5 | 0.01 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc. | ||
| CVE-2025-52603 | Low | 0.23 | 3.5 | 0.00 | Feb 20, 2026 | HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser. | ||
| CVE-2025-55249 | Low | 0.23 | 3.5 | 0.00 | Jan 19, 2026 | HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks. | ||
| CVE-2025-52639 | Low | 0.23 | 3.5 | 0.00 | Nov 18, 2025 | HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data. | ||
| CVE-2025-31995 | Low | 0.23 | 3.5 | 0.01 | Oct 13, 2025 | HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc. | ||
| CVE-2025-52615 | Low | 0.23 | 3.5 | 0.00 | Oct 12, 2025 | HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers. | ||
| CVE-2025-52614 | Low | 0.23 | 3.5 | 0.00 | Oct 12, 2025 | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site. | ||
| CVE-2025-31998 | Low | 0.23 | 3.5 | 0.00 | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service. | ||
| CVE-2025-31993 | Low | 0.23 | 3.5 | 0.00 | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server. | ||
| CVE-2025-52658 | Low | 0.23 | 3.5 | 0.00 | Oct 3, 2025 | HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited. | ||
| CVE-2024-42209 | Low | 0.23 | 3.5 | 0.00 | Jul 17, 2025 | HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data. | ||
| CVE-2024-42208 | Low | 0.23 | 3.5 | 0.00 | Apr 4, 2025 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | ||
| CVE-2024-30106 | Low | 0.23 | 3.5 | 0.00 | Oct 28, 2024 | HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data. | ||
| CVE-2023-50355 | Low | 0.23 | 3.6 | 0.00 | Oct 23, 2024 | HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack. | ||
| CVE-2024-30118 | Low | 0.23 | 3.5 | 0.00 | Oct 9, 2024 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data. | ||
| CVE-2023-37541 | Low | 0.23 | 3.5 | 0.00 | Jun 25, 2024 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | ||
| CVE-2024-30107 | Low | 0.23 | 3.5 | 0.00 | Apr 18, 2024 | HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. | ||
| CVE-2024-23557 | Low | 0.23 | 3.5 | 0.00 | Apr 18, 2024 | HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack. | ||
| CVE-2023-45715 | Low | 0.23 | 3.5 | 0.00 | Mar 28, 2024 | The console may experience a service interruption when processing file names with invalid characters. | ||
| CVE-2023-45705 | Low | 0.23 | 3.5 | 0.00 | Mar 28, 2024 | An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options. | ||
| CVE-2023-28022 | Low | 0.23 | 3.5 | 0.01 | Dec 15, 2023 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | ||
| CVE-2023-37511 | Low | 0.23 | 3.5 | 0.00 | Aug 11, 2023 | If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved. | ||
| CVE-2025-62315 | Low | 0.22 | 3.4 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | ||
| CVE-2025-62338 | Low | 0.21 | 3.3 | 0.00 | Jun 4, 2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure. | ||
| CVE-2025-52642 | Low | 0.21 | 3.3 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information… | ||
| CVE-2026-21791 | Low | 0.21 | 3.3 | 0.00 | Mar 10, 2026 | HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL | ||
| CVE-2026-21786 | Low | 0.21 | 3.3 | 0.00 | Mar 5, 2026 | HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs. | ||
| CVE-2025-0249 | Low | 0.21 | 3.3 | 0.00 | Jul 25, 2025 | HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization. | ||
| CVE-2023-37517 | Low | 0.21 | 3.2 | 0.00 | Apr 30, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. | ||
| CVE-2024-30127 | Low | 0.21 | 3.2 | 0.00 | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. | ||
| CVE-2023-37516 | Low | 0.21 | 3.2 | 0.00 | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits user directory information to be cached. | ||
| CVE-2024-30135 | Low | 0.21 | 3.3 | 0.00 | Jun 28, 2024 | HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken. | ||
| CVE-2024-30111 | Low | 0.21 | 3.3 | 0.00 | Jun 28, 2024 | HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially… | ||
| CVE-2023-37531 | Low | 0.21 | 3.3 | 0.00 | Feb 29, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access. | ||
| CVE-2023-37513 | Low | 0.21 | 3.3 | 0.00 | Aug 11, 2023 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | ||
| CVE-2023-37512 | Low | 0.21 | 3.3 | 0.00 | Aug 11, 2023 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. |
- risk 0.24cvss 3.7epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
- risk 0.24cvss 3.7epss 0.00
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
- risk 0.24cvss 3.7epss 0.00
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
- risk 0.24cvss 3.7epss 0.00
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.
- risk 0.24cvss 3.7epss 0.00
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
- risk 0.24cvss 3.7epss 0.00
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
- risk 0.24cvss 3.7epss 0.00
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.
- risk 0.24cvss 3.7epss 0.00
HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.
- risk 0.24cvss 3.7epss 0.00
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.
- risk 0.24cvss 3.7epss 0.00
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
- risk 0.24cvss 3.7epss 0.01
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.
- risk 0.24cvss 3.7epss 0.00
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.
- risk 0.23cvss 3.5epss 0.00
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
- risk 0.23cvss 3.5epss 0.00
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- risk 0.23cvss 3.5epss 0.01
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
- risk 0.23cvss 3.5epss 0.00
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.
- risk 0.23cvss 3.5epss 0.01
HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.
- risk 0.23cvss 3.5epss 0.00
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.
- risk 0.23cvss 3.5epss 0.00
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
- risk 0.23cvss 3.5epss 0.00
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.
- risk 0.23cvss 3.5epss 0.00
HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server.
- risk 0.23cvss 3.5epss 0.00
HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
- risk 0.23cvss 3.6epss 0.00
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
- risk 0.23cvss 3.5epss 0.00
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
- risk 0.23cvss 3.5epss 0.00
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
- risk 0.23cvss 3.5epss 0.00
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
- risk 0.23cvss 3.5epss 0.00
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.
- risk 0.23cvss 3.5epss 0.00
The console may experience a service interruption when processing file names with invalid characters.
- risk 0.23cvss 3.5epss 0.00
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
- risk 0.23cvss 3.5epss 0.01
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
- risk 0.23cvss 3.5epss 0.00
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
- risk 0.22cvss 3.4epss 0.00
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
- risk 0.21cvss 3.3epss 0.00
HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure.
- risk 0.21cvss 3.3epss 0.00
HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information…
- risk 0.21cvss 3.3epss 0.00
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL
- risk 0.21cvss 3.3epss 0.00
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
- risk 0.21cvss 3.3epss 0.00
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization.
- risk 0.21cvss 3.2epss 0.00
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
- risk 0.21cvss 3.2epss 0.00
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
- risk 0.21cvss 3.2epss 0.00
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
- risk 0.21cvss 3.3epss 0.00
HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.
- risk 0.21cvss 3.3epss 0.00
HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially…
- risk 0.21cvss 3.3epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
- risk 0.21cvss 3.3epss 0.00
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
- risk 0.21cvss 3.3epss 0.00
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
Page 9 of 12