Vendor CVEs
HCLTech
All CVEs
452 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-4324 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." | ||
| CVE-2019-4209 | Med | 0.40 | 6.1 | 0.01 | May 1, 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. | ||
| CVE-2022-38659 | Med | 0.39 | 6.0 | 0.00 | Dec 19, 2022 | In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent. | ||
| CVE-2022-27560 | Med | 0.39 | 6.0 | 0.00 | Aug 30, 2022 | HCL VersionVault Express exposes administrator credentials. | ||
| CVE-2020-4095 | Med | 0.39 | 6.0 | 0.00 | Jul 16, 2020 | "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.… | ||
| CVE-2025-55266 | Med | 0.38 | 5.9 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user. | ||
| CVE-2025-52644 | Med | 0.38 | 5.8 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation… | ||
| CVE-2025-36363 | Med | 0.38 | 5.9 | 0.00 | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | ||
| CVE-2024-22347 | Med | 0.38 | 5.9 | 0.00 | Jan 20, 2025 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | ||
| CVE-2024-30122 | Med | 0.38 | 5.8 | 0.00 | Oct 23, 2024 | HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers. | ||
| CVE-2024-23556 | Med | 0.38 | 5.9 | 0.00 | May 18, 2024 | SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability. | ||
| CVE-2023-37495 | Med | 0.38 | 5.9 | 0.00 | Feb 29, 2024 | Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the… | ||
| CVE-2023-50349 | Med | 0.38 | 5.9 | 0.00 | Feb 9, 2024 | Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application. | ||
| CVE-2023-37532 | Med | 0.38 | 5.8 | 0.01 | Oct 23, 2023 | HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system. | ||
| CVE-2023-28021 | Med | 0.38 | 5.9 | 0.00 | Jul 18, 2023 | The BigFix WebUI uses weak cipher suites. | ||
| CVE-2020-4099 | Med | 0.38 | 5.9 | 0.00 | Nov 1, 2022 | The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | ||
| CVE-2021-27784 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2022 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages. | ||
| CVE-2022-27558 | Med | 0.38 | 5.9 | 0.01 | Aug 29, 2022 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | ||
| CVE-2020-4126 | Med | 0.38 | 5.9 | 0.01 | Dec 1, 2020 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1… | ||
| CVE-2017-1712 | Med | 0.38 | 5.9 | 0.01 | Jul 1, 2020 | "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a… | ||
| CVE-2025-55267 | Med | 0.37 | 5.7 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | ||
| CVE-2024-23554 | Med | 0.37 | 5.7 | 0.00 | May 18, 2024 | Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). | ||
| CVE-2025-55264 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | ||
| CVE-2025-52627 | Med | 0.36 | 5.5 | 0.00 | Feb 3, 2026 | Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0. | ||
| CVE-2025-63402 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2025 | An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests | ||
| CVE-2025-63401 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2025 | Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives | ||
| CVE-2025-51733 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2024-42192 | Med | 0.36 | 5.5 | 0.00 | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | ||
| CVE-2024-30155 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2025 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF). | ||
| CVE-2024-42207 | Med | 0.36 | 5.5 | 0.00 | Feb 5, 2025 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session. | ||
| CVE-2023-28018 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2024 | HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users. | ||
| CVE-2023-28019 | Med | 0.36 | 5.5 | 0.00 | Jul 18, 2023 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | ||
| CVE-2022-38654 | Med | 0.36 | 5.5 | 0.00 | Nov 4, 2022 | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a… | ||
| CVE-2021-27755 | Med | 0.36 | 5.5 | 0.00 | Feb 21, 2022 | "Sametime Android potential path traversal vulnerability when using File class" | ||
| CVE-2021-27753 | Med | 0.36 | 5.5 | 0.00 | Feb 21, 2022 | "Sametime Android PathTraversal Vulnerability" | ||
| CVE-2020-4083 | Med | 0.36 | 5.5 | 0.00 | Mar 5, 2020 | HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. | ||
| CVE-2026-21788 | Med | 0.35 | 5.4 | 0.00 | Mar 19, 2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based… | ||
| CVE-2025-51734 | Med | 0.35 | 5.4 | 0.00 | Nov 28, 2025 | Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2025-31954 | Med | 0.35 | 5.4 | 0.00 | Nov 5, 2025 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were… | ||
| CVE-2025-52624 | Med | 0.35 | 5.4 | 0.00 | Oct 10, 2025 | A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects… | ||
| CVE-2024-42212 | Med | 0.35 | 5.4 | 0.00 | May 5, 2025 | HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions. | ||
| CVE-2024-42200 | Med | 0.35 | 5.4 | 0.00 | Apr 15, 2025 | HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input. | ||
| CVE-2024-30140 | Med | 0.35 | 5.4 | 0.00 | Nov 7, 2024 | HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page. | ||
| CVE-2024-30112 | Med | 0.35 | 5.4 | 0.00 | Jun 25, 2024 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based… | ||
| CVE-2023-37527 | Med | 0.35 | 5.4 | 0.00 | Feb 2, 2024 | A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page. | ||
| CVE-2023-50344 | Med | 0.35 | 5.4 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files. | ||
| CVE-2023-28017 | Med | 0.35 | 5.4 | 0.00 | Dec 7, 2023 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the… | ||
| CVE-2023-37533 | Med | 0.35 | 5.4 | 0.00 | Nov 9, 2023 | HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow… | ||
| CVE-2023-28012 | Med | 0.35 | 5.4 | 0.01 | Jul 27, 2023 | HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server. | ||
| CVE-2021-27782 | Med | 0.35 | 5.4 | 0.00 | Jan 20, 2023 | HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts. |
- risk 0.40cvss 6.1epss 0.01
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
- risk 0.40cvss 6.1epss 0.01
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
- risk 0.39cvss 6.0epss 0.00
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
- risk 0.39cvss 6.0epss 0.00
HCL VersionVault Express exposes administrator credentials.
- risk 0.39cvss 6.0epss 0.00
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…
- risk 0.38cvss 5.9epss 0.00
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
- risk 0.38cvss 5.8epss 0.00
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation…
- risk 0.38cvss 5.9epss 0.00
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
- risk 0.38cvss 5.9epss 0.00
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- risk 0.38cvss 5.8epss 0.00
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
- risk 0.38cvss 5.9epss 0.00
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
- risk 0.38cvss 5.9epss 0.00
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…
- risk 0.38cvss 5.9epss 0.00
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
- risk 0.38cvss 5.8epss 0.01
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
- risk 0.38cvss 5.9epss 0.00
The BigFix WebUI uses weak cipher suites.
- risk 0.38cvss 5.9epss 0.00
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
- risk 0.38cvss 5.9epss 0.00
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
- risk 0.38cvss 5.9epss 0.01
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
- risk 0.38cvss 5.9epss 0.01
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…
- risk 0.38cvss 5.9epss 0.01
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…
- risk 0.37cvss 5.7epss 0.00
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.
- risk 0.37cvss 5.7epss 0.00
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
- risk 0.36cvss 5.5epss 0.00
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
- risk 0.36cvss 5.5epss 0.00
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.
- risk 0.36cvss 5.5epss 0.00
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
- risk 0.36cvss 5.5epss 0.00
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
- risk 0.36cvss 5.5epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.36cvss 5.5epss 0.00
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
- risk 0.36cvss 5.5epss 0.00
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
- risk 0.36cvss 5.5epss 0.00
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.
- risk 0.36cvss 5.5epss 0.00
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
- risk 0.36cvss 5.5epss 0.00
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a…
- risk 0.36cvss 5.5epss 0.00
"Sametime Android potential path traversal vulnerability when using File class"
- risk 0.36cvss 5.5epss 0.00
"Sametime Android PathTraversal Vulnerability"
- risk 0.36cvss 5.5epss 0.00
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
- risk 0.35cvss 5.4epss 0.00
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based…
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.35cvss 5.4epss 0.00
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…
- risk 0.35cvss 5.4epss 0.00
A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects…
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
- risk 0.35cvss 5.4epss 0.00
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based…
- risk 0.35cvss 5.4epss 0.00
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
- risk 0.35cvss 5.4epss 0.00
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.
- risk 0.35cvss 5.4epss 0.00
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the…
- risk 0.35cvss 5.4epss 0.00
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow…
- risk 0.35cvss 5.4epss 0.01
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.
Page 4 of 10