VYPR

Vendor CVEs

HCLTech

All CVEs

452 total · sorted by risk
  • CVE-2021-27780MedMay 27, 2022
    risk 0.35cvss 5.3epss 0.01

    The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

  • CVE-2021-27769MedMay 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an…

  • CVE-2020-14270MedDec 22, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.

  • CVE-2020-14248MedDec 16, 2020
    risk 0.35cvss 5.3epss 0.01

    BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

  • CVE-2020-4128MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.

  • CVE-2020-4129MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.01

    HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and…

  • CVE-2020-4104MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in…

  • CVE-2019-4091MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "

  • CVE-2019-4090MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.01

    "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."

  • CVE-2020-4084MedMar 9, 2020
    risk 0.35cvss 5.4epss 0.01

    HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2020-4082MedMar 5, 2020
    risk 0.35cvss 5.4epss 0.01

    The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security…

  • CVE-2019-4409MedOct 18, 2019
    risk 0.35cvss 5.4epss 0.01

    HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message…

  • CVE-2025-31960MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the…

  • CVE-2025-31970MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)

  • CVE-2025-31981MedApr 21, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

  • CVE-2023-37525MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

  • CVE-2025-0275MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-0274MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-31996MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.

  • CVE-2025-52616MedOct 12, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.

  • CVE-2025-31977MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

  • CVE-2025-52621MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

  • CVE-2025-52619MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.

  • CVE-2024-42213MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2024-30154MedMar 3, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2024-30150MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.

  • CVE-2024-22348MedJan 20, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

  • CVE-2024-42172MedJan 11, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can…

  • CVE-2024-30133MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

  • CVE-2024-23586MedSep 27, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

  • CVE-2024-23562MedJul 8, 2024
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.

  • CVE-2024-23588MedJul 5, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

  • CVE-2019-4325MedOct 6, 2020
    risk 0.34cvss 5.3epss 0.01

    "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

  • CVE-2020-4092MedMay 6, 2020
    risk 0.34cvss 5.3epss 0.00

    "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…

  • CVE-2026-56567MedJul 31, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2022-27544MedJul 19, 2022
    risk 0.33cvss 5.0epss 0.00

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

  • CVE-2025-31988MedAug 19, 2025
    risk 0.32cvss 4.9epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.

  • CVE-2023-28023MedJul 18, 2023
    risk 0.32cvss 4.9epss 0.00

    A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 

  • CVE-2021-27778MedJun 1, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies,…

  • CVE-2020-14221MedFeb 2, 2021
    risk 0.32cvss 4.9epss 0.01

    HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.

  • CVE-2026-56609MedAug 3, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…

  • CVE-2025-31976MedMay 6, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .

  • CVE-2025-62320MedMar 17, 2026
    risk 0.31cvss 4.7epss 0.00

    HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically…

  • CVE-2025-52643MedMar 16, 2026
    risk 0.31cvss 4.7epss 0.00

    HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing…

  • CVE-2025-31987MedAug 14, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

  • CVE-2024-42173MedJan 11, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.

  • CVE-2024-30141MedNov 7, 2024
    risk 0.31cvss 4.7epss 0.00

    HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.

  • CVE-2024-30149MedOct 31, 2024
    risk 0.31cvss 4.8epss 0.00

    HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Page 5 of 10