Vendor CVEs
HCLTech
All CVEs
452 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4102 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2020 | HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system. | ||
| CVE-2020-4097 | Med | 0.44 | 6.8 | 0.00 | Nov 5, 2020 | In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an… | ||
| CVE-2023-28025 | Med | 0.43 | 6.6 | 0.00 | Dec 21, 2023 | Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before… | ||
| CVE-2023-23342 | Med | 0.43 | 6.6 | 0.00 | Aug 10, 2023 | If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. | ||
| CVE-2023-28014 | Med | 0.43 | 6.6 | 0.00 | Jul 27, 2023 | HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application. | ||
| CVE-2021-27781 | Med | 0.43 | 6.6 | 0.00 | May 27, 2022 | The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. | ||
| CVE-2025-15633 | Med | 0.42 | 6.5 | 0.00 | May 9, 2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate… | ||
| CVE-2025-55265 | Med | 0.42 | 6.5 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks. | ||
| CVE-2025-0277 | Med | 0.42 | 6.5 | 0.00 | Oct 16, 2025 | HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content. | ||
| CVE-2025-0276 | Med | 0.42 | 6.5 | 0.00 | Oct 16, 2025 | HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content. | ||
| CVE-2025-52632 | Med | 0.42 | 6.5 | 0.00 | Oct 10, 2025 | A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0. | ||
| CVE-2025-31972 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2025 | HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components. | ||
| CVE-2024-42191 | Med | 0.42 | 6.5 | 0.00 | May 30, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | ||
| CVE-2024-42190 | Med | 0.42 | 6.5 | 0.00 | May 30, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | ||
| CVE-2024-30145 | Med | 0.42 | 6.5 | 0.00 | Apr 30, 2025 | Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications. | ||
| CVE-2024-30152 | Med | 0.42 | 6.5 | 0.00 | Apr 25, 2025 | HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts. | ||
| CVE-2024-30147 | Med | 0.42 | 6.5 | 0.00 | Apr 24, 2025 | Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. | ||
| CVE-2024-42189 | Med | 0.42 | 6.5 | 0.00 | Apr 15, 2025 | HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter. | ||
| CVE-2024-42171 | Med | 0.42 | 6.4 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session. | ||
| CVE-2023-37528 | Med | 0.42 | 6.5 | 0.00 | Feb 3, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report. | ||
| CVE-2023-37518 | Med | 0.42 | 6.4 | 0.00 | Jan 30, 2024 | HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user. | ||
| CVE-2022-44758 | Med | 0.42 | 6.5 | 0.00 | Oct 11, 2023 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | ||
| CVE-2022-44757 | Med | 0.42 | 6.5 | 0.00 | Oct 11, 2023 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | ||
| CVE-2023-23347 | Med | 0.42 | 6.4 | 0.00 | Aug 9, 2023 | HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||
| CVE-2023-23346 | Med | 0.42 | 6.4 | 0.00 | Aug 9, 2023 | HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||
| CVE-2023-28013 | Med | 0.42 | 6.5 | 0.00 | Jul 26, 2023 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's… | ||
| CVE-2023-28009 | Med | 0.42 | 6.5 | 0.01 | Apr 26, 2023 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||
| CVE-2022-38655 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | ||
| CVE-2022-42446 | Med | 0.42 | 6.5 | 0.00 | Dec 12, 2022 | Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users. | ||
| CVE-2020-14225 | Med | 0.42 | 6.5 | 0.01 | Dec 21, 2020 | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing… | ||
| CVE-2020-4127 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2020 | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions… | ||
| CVE-2020-4089 | Med | 0.42 | 6.5 | 0.01 | Jun 26, 2020 | HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and… | ||
| CVE-2020-4085 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user." | ||
| CVE-2025-51736 | Med | 0.41 | 6.3 | 0.00 | Nov 28, 2025 | File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2024-30115 | Med | 0.41 | 6.3 | 0.00 | Apr 30, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | ||
| CVE-2024-30113 | Med | 0.41 | 6.3 | 0.00 | Apr 24, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | ||
| CVE-2021-27768 | Med | 0.41 | 6.3 | 0.00 | May 12, 2022 | Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in… | ||
| CVE-2026-21826 | Med | 0.40 | 6.1 | 0.00 | Jun 5, 2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | ||
| CVE-2026-21825 | Med | 0.40 | 6.1 | 0.00 | Jun 5, 2026 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser. | ||
| CVE-2025-36364 | Med | 0.40 | 6.2 | 0.00 | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. | ||
| CVE-2025-62326 | Med | 0.40 | 6.1 | 0.00 | Feb 20, 2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. | ||
| CVE-2024-30125 | Med | 0.40 | 6.2 | 0.00 | Jul 18, 2024 | HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die. | ||
| CVE-2022-38662 | Med | 0.40 | 6.1 | 0.00 | Dec 19, 2022 | In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. | ||
| CVE-2022-27547 | Med | 0.40 | 6.1 | 0.00 | Aug 29, 2022 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | ||
| CVE-2020-4081 | Med | 0.40 | 6.1 | 0.01 | Feb 2, 2021 | In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). | ||
| CVE-2020-14271 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2020 | HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web… | ||
| CVE-2020-4080 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2020 | HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser… | ||
| CVE-2020-14240 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting… | ||
| CVE-2020-14222 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | ||
| CVE-2020-14223 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack. |
- risk 0.44cvss 6.7epss 0.00
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system.
- risk 0.44cvss 6.8epss 0.00
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an…
- risk 0.43cvss 6.6epss 0.00
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before…
- risk 0.43cvss 6.6epss 0.00
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented.
- risk 0.43cvss 6.6epss 0.00
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
- risk 0.43cvss 6.6epss 0.00
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
- risk 0.42cvss 6.5epss 0.00
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate…
- risk 0.42cvss 6.5epss 0.00
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks.
- risk 0.42cvss 6.5epss 0.00
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
- risk 0.42cvss 6.5epss 0.00
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
- risk 0.42cvss 6.5epss 0.00
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
- risk 0.42cvss 6.5epss 0.00
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
- risk 0.42cvss 6.5epss 0.00
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
- risk 0.42cvss 6.5epss 0.00
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
- risk 0.42cvss 6.5epss 0.00
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
- risk 0.42cvss 6.5epss 0.00
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.
- risk 0.42cvss 6.5epss 0.00
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
- risk 0.42cvss 6.5epss 0.00
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
- risk 0.42cvss 6.4epss 0.00
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
- risk 0.42cvss 6.5epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
- risk 0.42cvss 6.4epss 0.00
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
- risk 0.42cvss 6.5epss 0.00
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
- risk 0.42cvss 6.5epss 0.00
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
- risk 0.42cvss 6.4epss 0.00
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- risk 0.42cvss 6.4epss 0.00
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- risk 0.42cvss 6.5epss 0.00
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's…
- risk 0.42cvss 6.5epss 0.01
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- risk 0.42cvss 6.4epss 0.00
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
- risk 0.42cvss 6.5epss 0.00
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.
- risk 0.42cvss 6.5epss 0.01
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing…
- risk 0.42cvss 6.5epss 0.00
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…
- risk 0.42cvss 6.5epss 0.01
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and…
- risk 0.42cvss 6.5epss 0.01
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
- risk 0.41cvss 6.3epss 0.00
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.41cvss 6.3epss 0.00
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
- risk 0.41cvss 6.3epss 0.00
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
- risk 0.41cvss 6.3epss 0.00
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in…
- risk 0.40cvss 6.1epss 0.00
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
- risk 0.40cvss 6.1epss 0.00
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
- risk 0.40cvss 6.2epss 0.00
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
- risk 0.40cvss 6.1epss 0.00
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
- risk 0.40cvss 6.2epss 0.00
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
- risk 0.40cvss 6.1epss 0.00
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
- risk 0.40cvss 6.1epss 0.00
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
- risk 0.40cvss 6.1epss 0.01
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web…
- risk 0.40cvss 6.1epss 0.01
HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser…
- risk 0.40cvss 6.1epss 0.01
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting…
- risk 0.40cvss 6.1epss 0.01
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
- risk 0.40cvss 6.1epss 0.01
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
Page 3 of 10