vciy

CVEs we hold for Hclsoftware

Records whose assigning authority named Hclsoftware as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-67071HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or TransferHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56620HCL BigFix Mobile is vulnerable to information disclosureHCLSoftware HCL BigFix Mobile
CVE-2026-56619HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS)HCLSoftware HCL BigFix Mobile
CVE-2026-56587HCL IEM was affected with Strict transport security not enforcedHCLSoftware IntelliOps Event Management
CVE-2026-56586HCL IEM was affected with X-Content-Type-Options Header MissingHCLSoftware IntelliOps Event Management
CVE-2026-56585HCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingHCLSoftware IntelliOps Event Management
CVE-2026-56584HCL IEM was affected with the Information disclosure nginx serverHCLSoftware IntelliOps Event Management
CVE-2026-56583HCL MyCloud was affected with Concurrent Login Vulnerability.HCLSoftware MyCloud
CVE-2026-56582HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.HCLSoftware MyCloud
CVE-2026-56581HCL MyCloud was affected with Cookie Attribute Path Not SetHCLSoftware MyCloud
CVE-2026-56580HCL MyCloud was affected by Using Components with Known VulnerabilityHCLSoftware MyCloud
CVE-2026-56579HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.HCLSoftware MyCloud
CVE-2026-56578HCL MyCloud was affected by Server Version DisclosureHCLSoftware MyCloud
CVE-2026-56577HCL MyCloud affected by Weak Password PolicyHCLSoftware MyCloud
CVE-2026-56547An input reflection vulnerability affects HCL TravelerHCLSoftware Traveler
CVE-2026-56538HCL Connections is vulnerable to information disclosureHCLSoftware Connections
CVE-2026-56537HCL Connections is vulnerable to information disclosureHCLSoftware Connections
CVE-2026-56460HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56459HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosureHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-56458HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted DomainsHCLSoftware HCL DevOps Deploy
CVE-2026-56457HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationHCLSoftware HCL DevOps Deploy / HCL Launch
CVE-2026-35146HCL DFXServer is affected by an Unencrypted Communication vulnerability.HCLSoftware DFXServer
CVE-2026-21840HCL BigFix Platform is affected by a user enumeration vulnerabilityHCLSoftware HCL BigFix Platform
CVE-2026-21837HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIHCLSoftware Digital Experience
CVE-2026-21836HCL DominoIQ is affected by broken access controlHCLSoftware DominoIQ
CVE-2026-21827HCL Connections is vulnerable to an information disclosure vulnerabilityHCLSoftware Connections
CVE-2026-21826HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionHCLSoftware Digital Experience & DX Compose
CVE-2026-21825HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search centerHCLSoftware DX Compose
CVE-2026-21824A privilege escalation vulnerability affects HCL CommerceHCLSoftware Commerce
CVE-2026-21821HCL BigFix SCM Reporting is affected by vulnerabilities in jQueryHCLSoftware BigFix SCM Reporting
CVE-2026-21810HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without…HCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21809HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive informationHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21808HCL BigFix Quantum Risk Analyzer is affected by logging sensitive informationHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21807HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflowHCLSoftware BigFix Quantum Risk Analyzer
CVE-2026-21790HCL Traveler is susceptible to a weak default HTTP header validation vulnerabilityHCLSoftware Traveler
CVE-2026-21789HCL Connections is vulnerable to broken access controlHCLSoftware Connections
CVE-2026-21788HCL Connections is vulnerable to cross-site scripting (XSS)HCLSoftware Connections
CVE-2026-21786HCL Sametime for iOS is affected by sensitive information disclosureHCLSoftware Sametime for iOS
CVE-2026-21785HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security PolicyHCLSoftware BigFix Remote Control Server
CVE-2026-21783HCL Traveler is affected by sensitive information disclosureHCLSoftware Traveler
CVE-2026-21770HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijackingHCLSoftware HCL Traveler for Microsoft Outlook (HTMO)
CVE-2026-21768HCL Verse for Android is susceptible to an injection vulnerabilityHCLSoftware Verse for Android
CVE-2026-21767HCL BigFix Platform is affected by insufficient authenticationHCLSoftware BigFix Platform
CVE-2026-21766HCL Digital Experience and Digital Experience Compose insufficiently protects credentialsHCLSoftware HCL Digital Experience and Digital Experience…
CVE-2026-21765HCL BigFix Platform is affected by insecure permissions on private cryptographic keysHCLSoftware BigFix Platform
CVE-2026-21764Insufficient Input Validation in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21762Missing HTTP Security Headers in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21761CORS Misconfiguration in DevOps LoopHCLSoftware DevOps Loop
CVE-2026-21760Unauthorized Access to Admin Functionality via Forced BrowsingHCLSoftware DevOps Loop
CVE-2026-21759HCL Hive is affected by an information exposure vulnerabilityHCLSoftware HCL Hive
CVE-2026-21756HCL Hive is affected by a broken access control vulnerabilityHCLSoftware HCL Hive
CVE-2026-21755HCL Hive is affected by a missing rate limitHCLSoftware HCL Hive
CVE-2026-21752HCL Hive is affected by a use of vulnerable third-party componentsHCLSoftware HCL Hive
CVE-2026-21751HCL Hive is affected by use of a cryptographic primitive with a risky implementationHCLSoftware HCL Hive
CVE-2025-68833HCL Hive is affected by use of a cryptographic primitive with a risky implementationHCLSoftware HCL Hive
CVE-2025-68825HCL Hive is affected by incorrect default permissionsHCLSoftware HCL Hive
CVE-2025-62341HCL Connections is vulnerable to server-side request forgery (SSRF)HCLSoftware Connections
CVE-2025-62338HCL BigFix Cloud Lifecycle Management is affected by lack of input validationHCLSoftware BigFix Cloud Lifecycle Management
CVE-2025-62328HCL Nomad server on Domino is affected by a missing default frame-ancestors directiveHCLSoftware Nomad server on Domino
CVE-2025-62327HCL DevOps Deploy is susceptible to insufficiently protected credentialsHCLSoftware DevOps Deploy
CVE-2025-62326HCL Digital Experience is susceptible to stored cross-site scripting (XSS)HCLSoftware Digital Experience
CVE-2025-59868HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposureHCLSoftware Traveler for Microsoft Outlook
CVE-2025-59866no title heldHCLSoftware DFXServer
CVE-2025-52603HCL Connections is vulnerable to information disclosureHCLSoftware Connections
CVE-2025-31991HCL DevOps Velocity is susceptible to brute-force attacksHCLSoftware Velocity
CVE-2025-31990HCL DevOps Velocity is susceptible to a Denial of Service vulnerabilityHCLSoftware HCL DevOps Velocity
CVE-2025-31981HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryptionHCLSoftware BigFix Service Management (SM)
CVE-2025-31964HCL BigFix IVR is impacted by an improper service binding configurationHCLSoftware BigFix IVR
CVE-2025-31963HCL BigFix IVR is impacted by improper authentication and missing CSRF protectionHCLSoftware BigFix IVR
CVE-2025-31962HCL BigFix IVR is impacted by an insufficient session expiration vulnerabilityHCLSoftware BigFix IVR
CVE-2025-31958HCL BigFix Service Management (SM) is susceptible to HTTP Request SmugglingHCLSoftware BigFix Service Management (SM)
CVE-2025-15634HCL BigFix WebUI is affected by a missing authorization vulnerabilityHCLSoftware BigFix WebUI
CVE-2025-15633HCL BigFix WebUI is affected by an improper authorization vulnerabilityHCLSoftware BigFix WebUI
CVE-2025-15619HCL Connections is vulnerable to broken access controlHCLSoftware Connections
CVE-2024-42214no title heldHCLSoftware Aftermarket EPC
CVE-2024-42210HCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS) vulnerabilityHCLSoftware Unica Marketing Operations (Plan)
CVE-2024-23581HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityHCLSoftware Traveler for Microsoft Outlook
CVE-2024-23578no title heldHCLSoftware Aftermarket EPC
CVE-2024-23577no title heldHCLSoftware Aftermarket EPC
CVE-2024-23575no title heldHCLSoftware Aftermarket EPC
CVE-2024-23574no title heldHCLSoftware Aftermarket EPC
CVE-2024-23573no title heldHCLSoftware Aftermarket EPC
CVE-2024-23572no title heldHCLSoftware Aftermarket EPC
CVE-2024-23571no title heldHCLSoftware Aftermarket EPC
CVE-2024-23570no title heldHCLSoftware Aftermarket EPC
CVE-2024-23569no title heldHCLSoftware Aftermarket EPC
CVE-2024-23568no title heldHCLSoftware Aftermarket EPC
CVE-2024-23567no title heldHCLSoftware Aftermarket EPC
CVE-2024-23566no title heldHCLSoftware Aftermarket EPC
CVE-2024-23565no title heldHCLSoftware Aftermarket EPC
CVE-2023-37525HCL BigFix Compliance is vulnerable to a sensitive information disclosureHCLSoftware BigFix Compliance
CVE-2023-37524HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of…HCLSoftware Traveler for Microsoft Outlook
CVE-2023-37508HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerabilityHCLSoftware DevOps Plan
CVE-2023-37507An information disclosure vulnerability affects HCL DevOps PlanHCLSoftware DevOps Plan

94 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.