VYPR
Vendor

HCLTech

HCL Technologies Limited is an Indian multinational information technology (IT) consulting company headquartered in Noida, Uttar Pradesh. Founded by Shiv Nadar, it was spun out in 1991 when HCL entered into the software services business. The company has offices in 60 countries and over 220,000 employees. It is the third-largest India-headquartered IT services company by revenue and market capitalization as of 2024.

Founded 1991
Products
95
CVEs
452
Across products
380
Status
Private

Products

95
View all 95 products →

Recent CVEs

452
View all 452 CVEs →
  • CVE-2025-62319CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently…

  • CVE-2022-44755CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44754CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44753CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44752CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44751CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44750CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2020-14224CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which…

  • CVE-2020-14268CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which…

  • CVE-2020-14244CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which…

  • CVE-2020-14260CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.

  • CVE-2020-4101CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

  • CVE-2019-4393CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard is vulnerable to excessive authorization attempts

  • CVE-2019-4392CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

  • CVE-2022-42447CriApr 2, 2023
    risk 0.62cvss 9.6epss 0.00

    HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.

  • CVE-2023-37538CriOct 11, 2023
    risk 0.60cvss 9.3epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

  • CVE-2023-37502CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.00

    HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.

  • CVE-2021-27779CriMay 25, 2022
    risk 0.59cvss 9.1epss 0.01

    VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

  • CVE-2024-42168HigJan 11, 2025
    risk 0.58cvss 8.9epss 0.00

    HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content.

  • CVE-2026-21837HigJun 5, 2026
    risk 0.57cvss 8.8epss 0.01

    HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a…