VYPR

Vendor CVEs

HCLTech

All CVEs

452 total · sorted by risk
  • CVE-2024-42177LowApr 17, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system.

  • CVE-2024-42176LowMar 19, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.

  • CVE-2024-42175LowJan 11, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like SQL injection, XSS, and buffer overflow.

  • CVE-2025-52661LowJan 19, 2026
    risk 0.16cvss 2.4epss 0.00

    HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.

  • CVE-2024-42178LowApr 17, 2025
    risk 0.16cvss 2.5epss 0.00

    HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.

  • CVE-2024-30117LowOct 14, 2024
    risk 0.16cvss 2.5epss 0.00

    A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

  • CVE-2023-23343LowJun 22, 2023
    risk 0.16cvss 2.4epss 0.00

    A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.

  • CVE-2021-27759LowMay 6, 2022
    risk 0.15cvss 2.3epss 0.00

    This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

  • CVE-2025-52646LowMar 16, 2026
    risk 0.14cvss 2.2epss 0.00

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information…

  • CVE-2025-31964LowJan 7, 2026
    risk 0.14cvss 2.2epss 0.00

    Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication…

  • CVE-2025-0250LowJul 25, 2025
    risk 0.14cvss 2.2epss 0.00

    HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.

  • CVE-2025-31962LowJan 7, 2026
    risk 0.13cvss 2.0epss 0.00

    Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

  • CVE-2025-0253LowJul 25, 2025
    risk 0.13cvss 2.0epss 0.00

    HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.

  • CVE-2024-42179LowJan 12, 2025
    risk 0.13cvss 2.0epss 0.00

    HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.

  • CVE-2023-45706LowMar 28, 2024
    risk 0.13cvss 2.0epss 0.00

    An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

  • CVE-2022-38653LowDec 19, 2022
    risk 0.13cvss 2.0epss 0.00

    In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

  • CVE-2025-52649LowMar 16, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific…

  • CVE-2025-52645LowMar 16, 2026
    risk 0.12cvss 1.9epss 0.00

    HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or…

  • CVE-2025-52636LowMar 16, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain…

  • CVE-2025-55250LowJan 19, 2026
    risk 0.12cvss 1.8epss 0.00

    HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.

  • CVE-2023-45716LowFeb 9, 2024
    risk 0.11cvss 1.7epss 0.00

    Sametime is impacted by sensitive information passed in URL.

  • CVE-2024-42181LowJan 12, 2025
    risk 0.10cvss 1.6epss 0.00

    HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2024-42180LowJan 12, 2025
    risk 0.10cvss 1.6epss 0.00

    HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

  • CVE-2026-56583LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

  • CVE-2026-56582LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

  • CVE-2026-56581LowJul 21, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

  • CVE-2026-56580LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

  • CVE-2026-56579LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

  • CVE-2026-56578LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

  • CVE-2026-56577LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

  • CVE-2026-56586LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

  • CVE-2026-56585LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

  • CVE-2026-56587LowJul 21, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

  • CVE-2026-56584LowJul 21, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

  • CVE-2023-37507HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

  • CVE-2023-37508MedJul 21, 2026
    risk 0.00cvss 6.1epss 0.00

    HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

  • CVE-2026-56456MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which…

  • CVE-2026-56455MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system…

  • CVE-2026-56454MedJul 16, 2026
    risk 0.00cvss 5.9epss 0.00

    HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all…

  • CVE-2026-56453MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or…

  • CVE-2026-35145LowJul 16, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to…

  • CVE-2026-35143LowJul 16, 2026
    risk 0.00cvss 3.0epss 0.00

    HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if…

  • CVE-2026-35142LowJul 16, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the…

  • CVE-2026-35141LowJul 16, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a…

  • CVE-2026-35140LowJul 16, 2026
    risk 0.00cvss 3.0epss 0.00

    HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic…

  • CVE-2026-35149HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized…

  • CVE-2026-35148MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without…

  • CVE-2026-35147HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform…

  • CVE-2026-35146MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted…

  • CVE-2025-59868MedJun 27, 2026
    risk 0.00cvss 5.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.

Page 9 of 10