VYPR

Vendor CVEs

HCLTech

All CVEs

452 total · sorted by risk
  • CVE-2019-4324MedJul 7, 2020
    risk 0.40cvss 6.1epss 0.01

    "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."

  • CVE-2019-4209MedMay 1, 2020
    risk 0.40cvss 6.1epss 0.01

    HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

  • CVE-2022-38659MedDec 19, 2022
    risk 0.39cvss 6.0epss 0.00

    In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

  • CVE-2022-27560MedAug 30, 2022
    risk 0.39cvss 6.0epss 0.00

    HCL VersionVault Express exposes administrator credentials.

  • CVE-2020-4095MedJul 16, 2020
    risk 0.39cvss 6.0epss 0.00

    "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…

  • CVE-2025-55266MedMar 26, 2026
    risk 0.38cvss 5.9epss 0.00

    HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

  • CVE-2025-52644MedMar 16, 2026
    risk 0.38cvss 5.8epss 0.00

    HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation…

  • CVE-2025-36363MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2024-22347MedJan 20, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-30122MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

  • CVE-2024-23556MedMay 18, 2024
    risk 0.38cvss 5.9epss 0.00

    SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

  • CVE-2023-37495MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…

  • CVE-2023-50349MedFeb 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.

  • CVE-2023-37532MedOct 23, 2023
    risk 0.38cvss 5.8epss 0.01

    HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

  • CVE-2023-28021MedJul 18, 2023
    risk 0.38cvss 5.9epss 0.00

    The BigFix WebUI uses weak cipher suites.

  • CVE-2020-4099MedNov 1, 2022
    risk 0.38cvss 5.9epss 0.00

    The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

  • CVE-2021-27784MedOct 31, 2022
    risk 0.38cvss 5.9epss 0.00

    The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

  • CVE-2022-27558MedAug 29, 2022
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

  • CVE-2020-4126MedDec 1, 2020
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…

  • CVE-2017-1712MedJul 1, 2020
    risk 0.38cvss 5.9epss 0.01

    "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…

  • CVE-2025-55267MedMar 26, 2026
    risk 0.37cvss 5.7epss 0.00

    HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.

  • CVE-2024-23554MedMay 18, 2024
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

  • CVE-2025-55264MedMar 26, 2026
    risk 0.36cvss 5.5epss 0.00

    HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.

  • CVE-2025-52627MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.

  • CVE-2025-63402MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests

  • CVE-2025-63401MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

  • CVE-2025-51733MedNov 28, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-42192MedOct 16, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.

  • CVE-2024-30155MedMar 26, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

  • CVE-2024-42207MedFeb 5, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

  • CVE-2023-28018MedFeb 12, 2024
    risk 0.36cvss 5.5epss 0.00

    HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

  • CVE-2023-28019MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.

  • CVE-2022-38654MedNov 4, 2022
    risk 0.36cvss 5.5epss 0.00

    HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a…

  • CVE-2021-27755MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android potential path traversal vulnerability when using File class"

  • CVE-2021-27753MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android PathTraversal Vulnerability"

  • CVE-2020-4083MedMar 5, 2020
    risk 0.36cvss 5.5epss 0.00

    HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

  • CVE-2026-21788MedMar 19, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based…

  • CVE-2025-51734MedNov 28, 2025
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2025-31954MedNov 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…

  • CVE-2025-52624MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects…

  • CVE-2024-42212MedMay 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

  • CVE-2024-42200MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

  • CVE-2024-30140MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.

  • CVE-2024-30112MedJun 25, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based…

  • CVE-2023-37527MedFeb 2, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.

  • CVE-2023-50344MedJan 3, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

  • CVE-2023-28017MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the…

  • CVE-2023-37533MedNov 9, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow…

  • CVE-2023-28012MedJul 27, 2023
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • CVE-2021-27782MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

Page 4 of 10