Vendor CVEs
HCLTech
All CVEs
452 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30126 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2024 | HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge. | ||
| CVE-2023-45698 | Med | 0.31 | 4.8 | 0.00 | Feb 10, 2024 | Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks. | ||
| CVE-2023-28020 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2023 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | ||
| CVE-2021-27762 | Med | 0.31 | 4.7 | 0.01 | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses | ||
| CVE-2021-27761 | Med | 0.31 | 4.8 | 0.00 | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks | ||
| CVE-2019-4388 | Med | 0.31 | 4.8 | 0.01 | Dec 18, 2019 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | ||
| CVE-2026-21760 | Med | 0.30 | 4.6 | 0.00 | Jul 17, 2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | ||
| CVE-2025-52613 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access. | ||
| CVE-2025-31978 | Med | 0.30 | 4.6 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other… | ||
| CVE-2025-52628 | Med | 0.30 | 4.6 | 0.00 | Feb 3, 2026 | HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0. | ||
| CVE-2025-52654 | Med | 0.30 | 4.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation. | ||
| CVE-2022-42450 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. | ||
| CVE-2022-42449 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications | ||
| CVE-2022-27562 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2025 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44760 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. | ||
| CVE-2022-44759 | Med | 0.30 | 4.6 | 0.00 | Apr 24, 2025 | Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. | ||
| CVE-2022-42451 | Med | 0.30 | 4.6 | 0.00 | Oct 11, 2023 | Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user. | ||
| CVE-2022-27545 | Med | 0.30 | 4.6 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. | ||
| CVE-2021-27786 | Med | 0.30 | 4.6 | 0.01 | Jun 9, 2022 | Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the… | ||
| CVE-2021-27760 | Med | 0.30 | 4.6 | 0.01 | May 6, 2022 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | ||
| CVE-2025-52626 | Med | 0.29 | 4.5 | 0.01 | Feb 3, 2026 | A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0 | ||
| CVE-2025-59872 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or… | ||
| CVE-2025-52606 | Med | 0.28 | 4.3 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is… | ||
| CVE-2025-15634 | Med | 0.28 | 4.3 | 0.00 | May 9, 2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | ||
| CVE-2025-55273 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | ||
| CVE-2025-55268 | Med | 0.28 | 4.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | ||
| CVE-2026-21783 | Med | 0.28 | 4.3 | 0.00 | Mar 24, 2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers… | ||
| CVE-2025-52620 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format. | ||
| CVE-2025-52618 | Med | 0.28 | 4.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries. | ||
| CVE-2025-0279 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's… | ||
| CVE-2025-0278 | Med | 0.28 | 4.3 | 0.00 | Apr 3, 2025 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. | ||
| CVE-2021-27758 | Med | 0.28 | 4.3 | 0.00 | May 6, 2022 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account. | ||
| CVE-2019-4323 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." | ||
| CVE-2026-21761 | Med | 0.27 | 4.2 | 0.00 | Jul 17, 2026 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. | ||
| CVE-2025-55269 | Med | 0.27 | 4.2 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. | ||
| CVE-2025-31997 | Med | 0.27 | 4.2 | 0.00 | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | ||
| CVE-2024-30146 | Med | 0.27 | 4.1 | 0.00 | Apr 30, 2025 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem. | ||
| CVE-2024-30148 | Med | 0.27 | 4.1 | 0.00 | Apr 24, 2025 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem. | ||
| CVE-2021-27773 | Med | 0.27 | 4.2 | 0.00 | May 12, 2022 | This vulnerability allows users to execute a clickjacking attack in the meeting's chat. | ||
| CVE-2026-56569 | Med | 0.26 | 4.0 | 0.00 | Jul 31, 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | ||
| CVE-2025-31973 | Med | 0.26 | 4.0 | 0.00 | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. | ||
| CVE-2026-21767 | Med | 0.26 | 4.0 | 0.00 | Apr 2, 2026 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | ||
| CVE-2025-31969 | Med | 0.26 | 4.0 | 0.00 | Oct 12, 2025 | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking. | ||
| CVE-2024-22349 | Med | 0.26 | 4.0 | 0.00 | Jan 20, 2025 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system. | ||
| CVE-2024-30124 | Med | 0.26 | 4.0 | 0.00 | Oct 23, 2024 | HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously. | ||
| CVE-2023-45696 | Med | 0.26 | 4.0 | 0.00 | Feb 10, 2024 | Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser. | ||
| CVE-2023-28010 | Med | 0.26 | 4.0 | 0.00 | Sep 8, 2023 | In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. | ||
| CVE-2025-31974 | Low | 0.25 | 3.9 | 0.00 | May 6, 2026 | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized… | ||
| CVE-2024-23563 | Low | 0.25 | 3.9 | 0.00 | Feb 12, 2025 | HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | ||
| CVE-2024-30142 | Low | 0.25 | 3.8 | 0.00 | Nov 7, 2024 | HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel. |
- risk 0.31cvss 4.7epss 0.00
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
- risk 0.31cvss 4.8epss 0.00
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
- risk 0.31cvss 4.7epss 0.00
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
- risk 0.31cvss 4.7epss 0.01
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
- risk 0.31cvss 4.8epss 0.00
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
- risk 0.31cvss 4.8epss 0.01
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
- risk 0.30cvss 4.6epss 0.00
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.
- risk 0.30cvss 4.6epss 0.00
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other…
- risk 0.30cvss 4.6epss 0.00
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
- risk 0.30cvss 4.6epss 0.00
HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
- risk 0.30cvss 4.6epss 0.00
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
- risk 0.30cvss 4.6epss 0.00
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
- risk 0.30cvss 4.6epss 0.01
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the…
- risk 0.30cvss 4.6epss 0.01
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
- risk 0.29cvss 4.5epss 0.01
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0
- risk 0.28cvss 4.3epss 0.00
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…
- risk 0.28cvss 4.3epss 0.00
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…
- risk 0.28cvss 4.3epss 0.00
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
- risk 0.28cvss 4.3epss 0.00
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers…
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
- risk 0.28cvss 4.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.
- risk 0.28cvss 4.3epss 0.00
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…
- risk 0.28cvss 4.3epss 0.00
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
- risk 0.28cvss 4.3epss 0.00
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
- risk 0.28cvss 4.3epss 0.01
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
- risk 0.27cvss 4.2epss 0.00
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
- risk 0.27cvss 4.2epss 0.00
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.
- risk 0.27cvss 4.2epss 0.00
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
- risk 0.27cvss 4.1epss 0.00
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
- risk 0.27cvss 4.1epss 0.00
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
- risk 0.27cvss 4.2epss 0.00
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
- risk 0.26cvss 4.0epss 0.00
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
- risk 0.26cvss 4.0epss 0.00
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
- risk 0.26cvss 4.0epss 0.00
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication.
- risk 0.26cvss 4.0epss 0.00
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
- risk 0.26cvss 4.0epss 0.00
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
- risk 0.26cvss 4.0epss 0.00
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
- risk 0.26cvss 4.0epss 0.00
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
- risk 0.26cvss 4.0epss 0.00
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
- risk 0.25cvss 3.9epss 0.00
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized…
- risk 0.25cvss 3.9epss 0.00
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
- risk 0.25cvss 3.8epss 0.00
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
Page 6 of 10