VYPR

Vendor CVEs

HCLTech

All CVEs

452 total · sorted by risk
  • CVE-2020-4102MedDec 2, 2020
    risk 0.44cvss 6.7epss 0.00

    HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system.

  • CVE-2020-4097MedNov 5, 2020
    risk 0.44cvss 6.8epss 0.00

    In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an…

  • CVE-2023-28025MedDec 21, 2023
    risk 0.43cvss 6.6epss 0.00

    Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before…

  • CVE-2023-23342MedAug 10, 2023
    risk 0.43cvss 6.6epss 0.00

    If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 

  • CVE-2023-28014MedJul 27, 2023
    risk 0.43cvss 6.6epss 0.00

    HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

  • CVE-2021-27781MedMay 27, 2022
    risk 0.43cvss 6.6epss 0.00

    The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

  • CVE-2025-15633MedMay 9, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate…

  • CVE-2025-55265MedMar 26, 2026
    risk 0.42cvss 6.5epss 0.00

    HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks.

  • CVE-2025-0277MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-0276MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-52632MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

  • CVE-2025-31972MedAug 28, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.

  • CVE-2024-42191MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2024-42190MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2024-30145MedApr 30, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-30152MedApr 25, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

  • CVE-2024-30147MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-42189MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

  • CVE-2024-42171MedJan 11, 2025
    risk 0.42cvss 6.4epss 0.00

    HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

  • CVE-2023-37528MedFeb 3, 2024
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.

  • CVE-2023-37518MedJan 30, 2024
    risk 0.42cvss 6.4epss 0.00

    HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.

  • CVE-2022-44758MedOct 11, 2023
    risk 0.42cvss 6.5epss 0.00

    BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.

  • CVE-2022-44757MedOct 11, 2023
    risk 0.42cvss 6.5epss 0.00

    BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.

  • CVE-2023-23347MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

  • CVE-2023-23346MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

  • CVE-2023-28013MedJul 26, 2023
    risk 0.42cvss 6.5epss 0.00

    HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's…

  • CVE-2023-28009MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2022-38655MedDec 21, 2022
    risk 0.42cvss 6.4epss 0.00

    BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

  • CVE-2022-42446MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

  • CVE-2020-14225MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.01

    HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing…

  • CVE-2020-4127MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…

  • CVE-2020-4089MedJun 26, 2020
    risk 0.42cvss 6.5epss 0.01

    HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and…

  • CVE-2020-4085MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

  • CVE-2025-51736MedNov 28, 2025
    risk 0.41cvss 6.3epss 0.00

    File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-30115MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2024-30113MedApr 24, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2021-27768MedMay 12, 2022
    risk 0.41cvss 6.3epss 0.00

    Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in…

  • CVE-2026-21826MedJun 5, 2026
    risk 0.40cvss 6.1epss 0.00

    HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

  • CVE-2026-21825MedJun 5, 2026
    risk 0.40cvss 6.1epss 0.00

    HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

  • CVE-2025-36364MedMar 3, 2026
    risk 0.40cvss 6.2epss 0.00

    IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

  • CVE-2025-62326MedFeb 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.

  • CVE-2024-30125MedJul 18, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

  • CVE-2022-38662MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.00

     In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

  • CVE-2022-27547MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.00

    HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.

  • CVE-2020-4081MedFeb 2, 2021
    risk 0.40cvss 6.1epss 0.01

    In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).

  • CVE-2020-14271MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web…

  • CVE-2020-4080MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser…

  • CVE-2020-14240MedNov 5, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting…

  • CVE-2020-14222MedNov 5, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

  • CVE-2020-14223MedOct 1, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.

Page 3 of 10