vciy

CVEs we hold for Hcl

Records whose assigning authority named Hcl as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9007Reflected XSS in HCL NotesHCL Notes
CVE-2026-67103HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-67102HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-67101HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-67100HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-67071HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or TransferHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56620HCL BigFix Mobile is vulnerable to information disclosureHCLSoftware HCL BigFix Mobile
CVE-2026-56619HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS)HCLSoftware HCL BigFix Mobile
CVE-2026-56609HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).HCL iControl
CVE-2026-56608HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).HCL iControl
CVE-2026-56597HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-56595HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-56592HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-56590HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-56587HCL IEM was affected with Strict transport security not enforcedHCLSoftware IntelliOps Event Management
CVE-2026-56586HCL IEM was affected with X-Content-Type-Options Header MissingHCLSoftware IntelliOps Event Management
CVE-2026-56585HCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingHCLSoftware IntelliOps Event Management
CVE-2026-56584HCL IEM was affected with the Information disclosure nginx serverHCLSoftware IntelliOps Event Management
CVE-2026-56583HCL MyCloud was affected with Concurrent Login Vulnerability.HCLSoftware MyCloud
CVE-2026-56582HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.HCLSoftware MyCloud
CVE-2026-56581HCL MyCloud was affected with Cookie Attribute Path Not SetHCLSoftware MyCloud
CVE-2026-56580HCL MyCloud was affected by Using Components with Known VulnerabilityHCLSoftware MyCloud
CVE-2026-56579HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.HCLSoftware MyCloud
CVE-2026-56578HCL MyCloud was affected by Server Version DisclosureHCLSoftware MyCloud
CVE-2026-56577HCL MyCloud affected by Weak Password PolicyHCLSoftware MyCloud
CVE-2026-56571HCL iControl is affected by multiple security vulnerabilities.HCL iControl
CVE-2026-56570HCL iControl is affected by multiple security vulnerabilities.HCL iControl
CVE-2026-56569HCL iControl is affected by multiple security vulnerabilities.HCL iControl
CVE-2026-56568HCL iControl is affected by multiple security vulnerabilities.HCL iControl
CVE-2026-56567HCL iControl is affected by multiple security vulnerabilities.HCL iControl
CVE-2026-56547An input reflection vulnerability affects HCL TravelerHCLSoftware Traveler
CVE-2026-56538HCL Connections is vulnerable to information disclosureHCLSoftware Connections
CVE-2026-56537HCL Connections is vulnerable to information disclosureHCLSoftware Connections
CVE-2026-56460HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56459HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosureHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56458HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted DomainsHCLSoftware HCL DevOps Deploy
CVE-2026-56457HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56456HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.HCL Software DFXAnalytics
CVE-2026-56455HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS).HCL Software DFXAnalytics
CVE-2026-56454HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.HCL Software DFXAnalytics
CVE-2026-56453HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.HCL Software DFXAnalytics
CVE-2026-35149HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.HCL Software DFXServer
CVE-2026-35148HCL DFXServer is affected by a Missing Access Control vulnerabilityHCL Software DFXServer
CVE-2026-35147HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.HCL Software DFXServer
CVE-2026-35146HCL DFXServer is affected by an Unencrypted Communication vulnerability.HCLSoftware DFXServer
CVE-2026-35145HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.HCL Software DFXAnalytics
CVE-2026-35143HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.HCL Software DFXAnalytics
CVE-2026-35142HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.HCL Software DFXAnalytics
CVE-2026-35141HCL DFXAnalytics is affected by a Login Replay Attack vulnerabilityHCL Software DFXAnalytics
CVE-2026-35140HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityHCL Software DFXAnalytics
CVE-2026-21848HCL BigFix Service Management is affected by multiple security vulnerabilities.HCL BigFix Service Management
CVE-2026-21840HCL BigFix Platform is affected by a user enumeration vulnerabilityHCLSoftware HCL BigFix Platform
CVE-2026-21837HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIHCLSoftware Digital Experience
CVE-2026-21836HCL DominoIQ is affected by broken access controlHCLSoftware DominoIQ
CVE-2026-21832HCL AION is affected by multiple security vulnerabilities.HCL Software AION
CVE-2026-21827HCL Connections is vulnerable to an information disclosure vulnerabilityHCLSoftware Connections
CVE-2026-21826HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionHCLSoftware Digital Experience & DX Compose
CVE-2026-21825HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search centerHCLSoftware DX Compose
CVE-2026-21824A privilege escalation vulnerability affects HCL CommerceHCLSoftware Commerce
CVE-2026-21822A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).HCL AppScan 360°
CVE-2026-21821HCL BigFix SCM Reporting is affected by vulnerabilities in jQueryHCLSoftware BigFix SCM Reporting
CVE-2026-21810HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without…HCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21809HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive informationHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21808HCL BigFix Quantum Risk Analyzer is affected by logging sensitive informationHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21807HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflowHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21806HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (CVE-2026-21806)HCL BigFix Service Management
CVE-2026-21791HCL Sametime for Android is affected by sensitive information disclosureHCL Sametime
CVE-2026-21790HCL Traveler is susceptible to a weak default HTTP header validation vulnerabilityHCLSoftware Traveler
CVE-2026-21789HCL Connections is vulnerable to broken access controlHCLSoftware Connections
CVE-2026-21788HCL Connections is vulnerable to cross-site scripting (XSS)HCLSoftware Connections
CVE-2026-21786HCL Sametime for iOS is affected by sensitive information disclosureHCLSoftware Sametime for iOS
CVE-2026-21785HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security PolicyHCLSoftware BigFix Remote Control Server
CVE-2026-21784HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2026-21783HCL Traveler is affected by sensitive information disclosureHCLSoftware Traveler
CVE-2026-21770HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijackingHCLSoftware HCL Traveler for Microsoft Outlook (HTMO)
CVE-2026-21768HCL Verse for Android is susceptible to an injection vulnerabilityHCLSoftware Verse for Android
CVE-2026-21767HCL BigFix Platform is affected by insufficient authenticationHCLSoftware BigFix Platform
CVE-2026-21766HCL Digital Experience and Digital Experience Compose insufficiently protects credentialsHCLSoftware HCL Digital Experience and Digital Experience…
CVE-2026-21765HCL BigFix Platform is affected by insecure permissions on private cryptographic keysHCLSoftware BigFix Platform
CVE-2026-21764Insufficient Input Validation in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21762Missing HTTP Security Headers in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21761CORS Misconfiguration in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21760Unauthorized Access to Admin Functionality via Forced BrowsingHCLSoftware DevOps Loop
CVE-2026-21759HCL Hive is affected by an information exposure vulnerabilityHCLSoftware HCL Hive
CVE-2026-21758HCL Hive is affected by multiple security vulnerabilities.HCL Software Hive
CVE-2026-21756HCL Hive is affected by a broken access control vulnerabilityHCLSoftware HCL Hive
CVE-2026-21755HCL Hive is affected by a missing rate limitHCLSoftware HCL Hive
CVE-2026-21754HCL Hive is affected by multiple security vulnerabilities.HCL Software Hive
CVE-2026-21753HCL Hive is affected by multiple security vulnerabilities.HCL Software Hive
CVE-2026-21752HCL Hive is affected by a use of vulnerable third-party componentsHCLSoftware HCL Hive
CVE-2026-21751HCL Hive is affected by use of a cryptographic primitive with a risky implementationHCLSoftware HCL Hive
CVE-2025-68833HCL Hive is affected by use of a cryptographic primitive with a risky implementationHCLSoftware HCL Hive
CVE-2025-68825HCL Hive is affected by incorrect default permissionsHCLSoftware HCL Hive
CVE-2025-62347no title heldHCL iControl
CVE-2025-62346HCL Glovius Cloud is susceptible to a Cross-Site Request Forgery (CSRF) vulnerabilityHCL Software Glovius Cloud
CVE-2025-62345HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” VulnerabilityHCL BigFix RunBookAI
CVE-2025-62343HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL IEM
CVE-2025-62342HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2025-62341HCL Connections is vulnerable to server-side request forgery (SSRF)HCLSoftware Connections
CVE-2025-62340HCL iControl was affected by Inadequate Session Timeout vulnerabilityHCL Software iControl
CVE-2025-62338HCL BigFix Cloud Lifecycle Management is affected by lack of input validationHCLSoftware BigFix Cloud Lifecycle Management
CVE-2025-62330HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationHCL Software DevOps Deploy
CVE-2025-62329HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerabilityHCL Software DevOps Deploy / Launch
CVE-2025-62328HCL Nomad server on Domino is affected by a missing default frame-ancestors directiveHCLSoftware Nomad server on Domino
CVE-2025-62327HCL DevOps Deploy is susceptible to insufficiently protected credentialsHCLSoftware DevOps Deploy
CVE-2025-62326HCL Digital Experience is susceptible to stored cross-site scripting (XSS)HCLSoftware Digital Experience
CVE-2025-62320HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica PlatformHCL Sametime
CVE-2025-62319Boolean-Based SQL Injection in Multiple Unica ComponentsHCL Unica
CVE-2025-62318HCL AION is affected by multiple security vulnerabilities.HCL Software AION
CVE-2025-62317HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.HCL AION
CVE-2025-62316HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configuredHCL AION
CVE-2025-62315HCL AION is affected by multiple security vulnerabilities.HCL Software AION
CVE-2025-62314HCL AION is affected by multiple security vulnerabilities.HCL Software AION
CVE-2025-62313HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.HCL AION
CVE-2025-62312HCL AION is affected by a vulnerability where basic authorization tokens are used for authenticationHCL AION
CVE-2025-62311HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.HCL AION
CVE-2025-62310HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operationsHCL AION
CVE-2025-62309HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.HCL AION
CVE-2025-62308HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposedHCL AION
CVE-2025-62307HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2025-62306HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2025-62305HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactionsHCL AION
CVE-2025-62300HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2025-62299HCL IntelliOps Event Management is affected by multiple security vulnerabilities.HCL Software IEM
CVE-2025-59874HCL Hive Telco Observability is affected by  a Required directives missing from the CSP .HCL Hive
CVE-2025-59873Session Token Exposure via URL Query ParametersHCL Software ZIE for Web
CVE-2025-59872HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,HCL Software ZIE
CVE-2025-59870Improper management of a static JWT signing secret in the web application, where the secret lacks rotation…HCL Software MyXalytics
CVE-2025-59868HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposureHCLSoftware Traveler for Microsoft Outlook
CVE-2025-59866no title heldHCLSoftware DFXServer
CVE-2025-59854HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerabilityHCL DFXAnalytics
CVE-2025-59853HCL DFXAnalytics is affected by an Improper Error Handling vulnerabilityHCL DFXAnalytics
CVE-2025-59852HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerabilityHCL DFXAnalytics
CVE-2025-59851HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerabilityHCL DFXAnalytics
CVE-2025-59849HCL BigFix Remote Control is vulnerable to an insecure CSP configurationHCL Software BigFix Remote Control
CVE-2025-55278HCL DevOps Loop is susceptible to an improper authentication vulnerabilityHCL Software DevOps Loop
CVE-2025-55277HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerabilityHCL Aftermarket DPC
CVE-2025-55276HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerabilityHCL Aftermarket DPC
CVE-2025-55275HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerabilityHCL Aftermarket DPC
CVE-2025-55274HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerabilityHCL Aftermarket DPC
CVE-2025-55273HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerabilityHCL Aftermarket DPC
CVE-2025-55272HCL Aftermarket DPC is affected by Banner Disclosure vulnerabilityHCL Aftermarket DPC
CVE-2025-55271HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerabilityHCL Aftermarket DPC
CVE-2025-55270HCL Aftermarket DPC is affected by Improper Input ValidationHCL Aftermarket DPC
CVE-2025-55269HCL Aftermarket DPC is affected by Weak Password Policy vulnerabilityHCL Aftermarket DPC
CVE-2025-55268HCL Aftermarket DPC is affected by Spamming VulnerabilityHCL Aftermarket DPC
CVE-2025-55267HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerabilityHCL Aftermarket DPC
CVE-2025-55266HCL Aftermarket DPC is affected by Session FixationHCL Aftermarket DPC
CVE-2025-55265HCL Aftermarket DPC is affected by File DiscoveryHCL Aftermarket DPC
CVE-2025-55264HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password ChangeHCL Aftermarket DPC
CVE-2025-55263HCL Aftermarket DPC is affected by Hardcoded Sensitive DataHCL Aftermarket DPC
CVE-2025-55262HCL Aftermarket DPC is affected by SQL InjectionHCL Aftermarket DPC
CVE-2025-55261HCL Aftermarket DPC is affected by Missing Functional Level Access ControlHCL Aftermarket DPC
CVE-2025-55254HCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI)HCL Software BigFix Remote Control
CVE-2025-55252HCL AION is affected by a Weak Password Policy vulnerabilityHCL Software AION
CVE-2025-55251HCL AION is affected by an Unrestricted File Upload vulnerabilityHCL Software AION
CVE-2025-55250HCL AION is affected by a Technical Error Disclosure vulnerabilityHCL Software AION
CVE-2025-55249HCL AION is affected by a Missing Security Response Headers vulnerability.HCL Software AION
CVE-2025-52661no title heldHCL Software AION
CVE-2025-52660HCL AION is affected by an Host Header Injection vulnerabilityHCL Software AION
CVE-2025-52659HCL AION is affected by a Cacheable HTTP Response vulnerabilityHCL Software AION
CVE-2025-52658HCL MyXalytics is affected by the use of vulnerable/outdated versionsHCL Software MyXalytics
CVE-2025-52657HCL MyXalytics is affected by multiple security vulnerabilities.HCL Software MyXalytics
CVE-2025-52656HCL MyXalytics product is affected by Mass Assignment vulnerabilityHCL MyXalytics
CVE-2025-52655HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.HCL MyXalytics
CVE-2025-52654HCL MyXalytics is affected by an HTML InjectionHCL MyXalytics
CVE-2025-52653Cross Site Scripting vulnerability in the web applicationHCL MyXalytics
CVE-2025-52652HCL MyXalytics is affected by multiple security vulnerabilities.HCL Software MyXalytics
CVE-2025-52651HCL MyXalytics is affected by multiple security vulnerabilities.HCL Software MyXalytics
CVE-2025-52650HCL AION is susceptible to Inline script execution allowed in CSP vulnerabilityHCL AION
CVE-2025-52649HCL AION is affected by a vulnerability where certain identifiers may be predictable in natureHCL AION
CVE-2025-52648no title heldHCL AION
CVE-2025-52647HCL BigFix WebUI is affected by a host header poisoning vulnerabilityHCL Software BigFix WebUI
CVE-2025-52646HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially…HCL AION
CVE-2025-52645HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient…HCL AION
CVE-2025-52644HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.HCL AION
CVE-2025-52643HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly…HCL AION
CVE-2025-52642HCL AION is affected by an internal filesystem paths disloser vulnerabilityHCL AION
CVE-2025-52641Internal Filesystem Exploration vulnerabilityHCL AION
CVE-2025-52640HCL AION is affected by multiple security vulnerabilities.HCL Software AION
CVE-2025-52639HCL Connections is vulnerable to sensitive information disclosureHCL Software Connections
CVE-2025-52638Multiple security vulnerabilities affect HCL AIONHCL AION
CVE-2025-52637Multiple security vulnerabilities affect HCL AIONHCL AION
CVE-2025-52636HCL AION is affected by a improper handling of uploads files SizeHCL AION
CVE-2025-52635HCL AION is susceptible to Trusted types in scripts not enforced in CSPHCL AION
CVE-2025-52634HCL AION is susceptible to Spring Boot Actuator Endpoints ExposedHCL AION
CVE-2025-52633HCL AION is susceptible to Missing Content-Security-PolicyHCL AION
CVE-2025-52632HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityHCL AION
CVE-2025-52631HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.HCL AION
CVE-2025-52630HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerabilityHCL AION
CVE-2025-52629HCL AION is susceptible to Missing Content-Security-PolicyHCL AION
CVE-2025-52628HCL AION is susceptible to Missing SameSite vulnerabilityHCL AION
CVE-2025-52627HCL AION is susceptible to Incorrect Permission Assignment for Critical ResourceHCL AION
CVE-2025-52626HCL AION is susceptible to Potential Command Injection vulnerabilityHCL AION
CVE-2025-52625HCL AION is susceptible to Cacheable SSL Page Found vulnerabilityHCL AION
CVE-2025-52624HCL AION is susceptible to Bypass of the script allow list configuration vulnerabilityHCL AION
CVE-2025-52623HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerabilityHCL AION
CVE-2025-52622HCL BigFix SaaS Remediate is affected by a security vulnerabilityHCL Software BigFix SaaS Remediate
CVE-2025-52621HCL BigFix SaaS Authentication Service is vulnerable to cache poisoningHCL Software BigFix SaaS Remediate
CVE-2025-52620HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerabilityHCL Software BigFix SaaS Remediate

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.