Search Results (439 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-56457 1 Hcltech 1 Devops Deploy 2026-06-29 4.3 Medium
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
CVE-2024-23581 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 6.7 Medium
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
CVE-2023-37524 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 7.7 High
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components.
CVE-2025-59868 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 5.5 Medium
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
CVE-2025-59872 1 Hcltech 1 Zie For Web 2026-06-26 4.3 Medium
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2025-15619 1 Hcltech 1 Connections 2026-06-24 3.5 Low
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
CVE-2025-62340 1 Hcltech 1 Icontrol 2026-06-20 3.1 Low
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVE-2026-21837 1 Hcltech 2 Digital Experience, Digital Experience Compose 2026-06-10 8.8 High
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
CVE-2026-21826 1 Hcltech 3 Digital Experience, Digital Experience Compose, Dx Compose 2026-06-10 6.1 Medium
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
CVE-2026-21825 1 Hcltech 3 Digital Experience, Digital Experience Compose, Dx Compose 2026-06-10 6.1 Medium
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.
CVE-2025-62319 1 Hcltech 2 Unica, Unica Audience Central 2026-06-05 9.8 Critical
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.
CVE-2025-59874 1 Hcltech 1 Hive 2026-06-05 8.1 High
HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
CVE-2025-62338 1 Hcltech 1 Bigfix Cloud Lifecycle Management 2026-06-05 3.3 Low
HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized access and may lead to information exposure.
CVE-2025-52606 1 Hcltech 1 Icontrol 2026-06-04 4.3 Medium
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CVE-2025-52608 1 Hcltech 1 Icontrol 2026-06-04 3.1 Low
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVE-2025-52609 1 Hcltech 1 Icontrol 2026-06-04 3.7 Low
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
CVE-2025-52611 1 Hcltech 1 Icontrol 2026-06-04 3.1 Low
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object.
CVE-2025-52612 1 Hcltech 1 Icontrol 2026-06-04 7.1 High
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
CVE-2026-21785 1 Hcltech 1 Bigfix Remote Control 2026-05-29 4 Medium
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
CVE-2025-31973 1 Hcltech 1 Bigfix Service Management 2026-05-20 4 Medium
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.