Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Aftermarket Cloud MEDIUM 5.5
CVE-2025-55264

HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintai…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55261

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55262

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud HIGH 8.1
CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or imper…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 6.5
CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available a…

No fix yet
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55269

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 8.8
CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55268

HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55267

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55265

HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 6.5
CVE-2025-55266

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transactio…

Mitigation only
Fix from $1,600 2026-03-26
Connections MEDIUM 5.4
CVE-2026-21788

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Mitigation only
Fix from $1,600 2026-03-19
Aion HIGH 8.8
CVE-2025-52628

HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site request…

Mitigation only
Fix from $1,950 2026-02-03
Aion HIGH 8.1
CVE-2025-52631

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potent…

Mitigation only
Fix from $1,950 2026-02-03
Aion MEDIUM 6.5
CVE-2025-52623

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields…

Mitigation only
Fix from $1,600 2026-02-03
Aion MEDIUM 5.3
CVE-2025-52633

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent…

Mitigation only
Fix from $1,600 2026-02-03
Aion HIGH 7.5
CVE-2025-52627

Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially …

Mitigation only
Fix from $1,950 2026-02-03
Aion MEDIUM 6.1
CVE-2025-52629

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other …

Mitigation only
Fix from $1,600 2026-02-03
Aion CRITICAL 9.8
CVE-2025-52626

A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio…

Mitigation only
Fix from $2,300 2026-02-03
Bigfix Compliance MEDIUM 5.3
CVE-2023-37525

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain J…

Mitigation only
Fix from $1,600 2026-01-28
Aion CRITICAL 9.8
CVE-2025-55252

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting…

Mitigation only
Fix from $2,300 2026-01-19
Aion MEDIUM 5.3
CVE-2025-55250

HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in i…

No fix yet
Fix from $1,600 2026-01-19
Aion CRITICAL 9.8
CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Aion MEDIUM 5.3
CVE-2025-55249

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s over…

Mitigation only
Fix from $1,600 2026-01-19
Aion CRITICAL 9.8
CVE-2025-52660

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Aion HIGH 7.5
CVE-2025-52659

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, poten…

Mitigation only
Fix from $1,950 2026-01-19
Aion MEDIUM 5.3
CVE-2025-52661

HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in una…

Mitigation only
Fix from $1,600 2026-01-19