Vulnerability index

Browse CVEs

177 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Myxalytics CRITICAL 9.8
CVE-2025-59870

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci…

Mitigation only
Fix from $2,300 2026-01-16
Unica HIGH 7.5
CVE-2025-51735

CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Mitigation only
Fix from $1,950 2025-11-28
Unica MEDIUM 6.3
CVE-2025-51736

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Unica MEDIUM 5.5
CVE-2025-51733

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Unica MEDIUM 5.4
CVE-2025-51734

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Connections MEDIUM 6.5
CVE-2025-52639

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are n…

Mitigation only
Fix from $1,600 2025-11-18
Unica HIGH 7.5
CVE-2025-52616

HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnera…

No fix yet
Fix from $1,950 2025-10-12
Aion CRITICAL 9.8
CVE-2025-52635

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

No fix yet
Fix from $2,300 2025-10-10
Aion HIGH 7.5
CVE-2025-52625

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers,…

Mitigation only
Fix from $1,950 2025-10-10
Aion MEDIUM 6.1
CVE-2025-52624

A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unaut…

Mitigation only
Fix from $1,600 2025-10-10
Aion HIGH 7.5
CVE-2025-52634

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10
Aion MEDIUM 6.1
CVE-2025-52650

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Mitigation only
Fix from $1,600 2025-10-10
Aion HIGH 7.5
CVE-2025-52630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10
Aion HIGH 7.5
CVE-2025-52632

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Mitigation only
Fix from $1,950 2025-10-10
Dryice Myxalytics HIGH 7.6
CVE-2025-52656

HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application obje…

Mitigation only
Fix from $1,950 2025-10-03
Dryice Myxalytics MEDIUM 5.4
CVE-2025-52653

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts…

Mitigation only
Fix from $1,600 2025-10-03
Bigfix Service Management MEDIUM 6.5
CVE-2025-31972

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an…

Mitigation only
Fix from $1,600 2025-08-28
Bigfix Service Management MEDIUM 6.5
CVE-2025-31977

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit thi…

Mitigation only
Fix from $1,600 2025-08-28
Connections Docs HIGH 7.5
CVE-2025-31987

HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

Mitigation only
Fix from $1,950 2025-08-14
Intelliops Event Management MEDIUM 5.7
CVE-2025-0251

HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the same user credentials, which …

Mitigation only
Fix from $1,600 2025-07-25
Intelliops Event Management MEDIUM 5.9
CVE-2025-0249

HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to acces…

Mitigation only
Fix from $1,600 2025-07-25
Dryice Iautomate HIGH 7.1
CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing…

Mitigation only
Fix from $1,950 2025-07-24
Dryice Iautomate MEDIUM 6.5
CVE-2025-31953

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p…

Mitigation only
Fix from $1,600 2025-07-24
Dryice Iautomate MEDIUM 6.5
CVE-2025-31955

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s…

No fix yet
Fix from $1,600 2025-07-24
Bigfix Compliance MEDIUM 5.4
CVE-2024-42212

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a …

Mitigation only
Fix from $1,600 2025-05-05
Bigfix Compliance MEDIUM 5.3
CVE-2024-42213

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files b…

Mitigation only
Fix from $1,600 2025-05-05
Domino Leap MEDIUM 5.4
CVE-2022-42450

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

Mitigation only
Fix from $1,600 2025-04-30
Hcl Sx CRITICAL 9.8
CVE-2024-30152

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, …

Mitigation only
Fix from $2,300 2025-04-25
Dryice Myxalytics HIGH 7.5
CVE-2024-42178

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con…

Mitigation only
Fix from $1,950 2025-04-17
Dryice Myxalytics MEDIUM 6.4
CVE-2024-42177

HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to i…

Mitigation only
Fix from $1,600 2025-04-17