VYPR

Vendor CVEs

HCLTech

All CVEs

452 total · sorted by risk
  • CVE-2023-37541LowJun 25, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2024-30107LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

  • CVE-2024-23557LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.

  • CVE-2023-45715LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    The console may experience a service interruption when processing file names with invalid characters.

  • CVE-2023-45705LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

  • CVE-2023-28022LowDec 15, 2023
    risk 0.23cvss 3.5epss 0.01

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.

  • CVE-2023-37511LowAug 11, 2023
    risk 0.23cvss 3.5epss 0.00

    If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.

  • CVE-2025-52642LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information…

  • CVE-2026-21791LowMar 10, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL

  • CVE-2026-21786LowMar 5, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

  • CVE-2025-0249LowJul 25, 2025
    risk 0.21cvss 3.3epss 0.00

    HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to access sensitive data without authorization.

  • CVE-2023-37517LowApr 30, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

  • CVE-2024-30127LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

  • CVE-2023-37516LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits user directory information to be cached.

  • CVE-2024-30135LowJun 28, 2024
    risk 0.21cvss 3.3epss 0.00

    HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

  • CVE-2024-30111LowJun 28, 2024
    risk 0.21cvss 3.3epss 0.00

    HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially…

  • CVE-2023-37531LowFeb 29, 2024
    risk 0.21cvss 3.3epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.

  • CVE-2023-37513LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

  • CVE-2023-37512LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

  • CVE-2026-21764LowJul 17, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

  • CVE-2025-62340LowJun 17, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

  • CVE-2025-52611LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object…

  • CVE-2025-52608LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

  • CVE-2025-59854LowMay 6, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead…

  • CVE-2025-59853LowMay 6, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.

  • CVE-2025-55276LowMar 26, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

  • CVE-2025-55272LowMar 26, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks.

  • CVE-2025-55271LowMar 26, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response..

  • CVE-2025-52633LowFeb 3, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.

  • CVE-2025-55252LowJan 19, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access

  • CVE-2025-55251LowJan 19, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

  • CVE-2023-37530LowFeb 29, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.

  • CVE-2023-37529LowFeb 29, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in…

  • CVE-2024-23553LowFeb 2, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

  • CVE-2023-50348LowJan 3, 2024
    risk 0.20cvss 3.1epss 0.00

    HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.

  • CVE-2023-50346LowJan 3, 2024
    risk 0.20cvss 3.1epss 0.00

    HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information.

  • CVE-2023-23344LowJun 23, 2023
    risk 0.20cvss 3.0epss 0.00

    A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

  • CVE-2023-28016LowJun 22, 2023
    risk 0.20cvss 3.1epss 0.00

    Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.

  • CVE-2021-27774LowSep 22, 2022
    risk 0.20cvss 3.1epss 0.00

    User input included in error response, which could be used in a phishing attack.

  • CVE-2025-52641LowApr 15, 2026
    risk 0.19cvss 2.9epss 0.00

    HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited…

  • CVE-2025-31963LowJan 7, 2026
    risk 0.19cvss 2.9epss 0.00

    Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.

  • CVE-2025-31966LowMar 17, 2026
    risk 0.18cvss 2.7epss 0.00

    HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

  • CVE-2025-52660LowJan 19, 2026
    risk 0.18cvss 2.7epss 0.00

    HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

  • CVE-2025-52659LowJan 19, 2026
    risk 0.18cvss 2.8epss 0.00

    HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.

  • CVE-2025-31975LowMay 6, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities.

  • CVE-2025-31957LowMay 6, 2026
    risk 0.17cvss 2.6epss 0.00

    HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

  • CVE-2025-55277LowMar 26, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application.

  • CVE-2025-55274LowMar 26, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS…

  • CVE-2025-0252LowJul 25, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.

  • CVE-2025-0251LowJul 25, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.

Page 8 of 10