Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-56609
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TL…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56608
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56570
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56571
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa…
Icontrol
No fix yet
MEDIUM 5.3
CVE-2026-56568
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra…
Icontrol
No fix yet
MEDIUM 6.5
CVE-2026-56577
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
Dryice Mycloud
No fix yet
MEDIUM 5.3
CVE-2026-56584
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vu…
Intelliops Event Management
No fix yet
MEDIUM 5.3
CVE-2026-21762
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attack…
Devops Loop
No fix yet
MEDIUM 5.4
CVE-2026-21761
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-orig…
Devops Loop
No fix yet
CRITICAL 9.8
CVE-2025-59872
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obt…
Zie For Web
Mitigation only
MEDIUM 5.3
CVE-2025-62340
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to au…
Icontrol
Mitigation only
HIGH 8.8
CVE-2026-21837
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary o…
Digital Experience
Mitigation only
MEDIUM 6.1
CVE-2026-21825
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute a…
Digital Experience Compose
Mitigation only
MEDIUM 6.1
CVE-2026-21826
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header …
Digital Experience Compose
Mitigation only
HIGH 8.8
CVE-2025-52612
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was c…
Icontrol
Mitigation only
MEDIUM 5.3
CVE-2025-52609
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS fi…
Icontrol
Mitigation only
CRITICAL 9.8
CVE-2025-31973
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images …
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31985
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…
Bigfix Service Management
Mitigation only
HIGH 8.3
CVE-2024-30151
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz…
Bigfix Service Management
Mitigation only
HIGH 7.2
CVE-2025-31974
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31960
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed …
Bigfix Service Management
Mitigation only
HIGH 8.8
CVE-2025-52613
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e…
Bigfix Service Management
Mitigation only
MEDIUM 5.4
CVE-2025-31984
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…
Bigfix Service Management
Mitigation only
HIGH 7.5
CVE-2025-31976
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31982
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…
Bigfix Service Management
Mitigation only
MEDIUM 5.7
CVE-2025-31957
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exp…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31975
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s…
Bigfix Service Management
Mitigation only
HIGH 8.2
CVE-2025-31958
HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route HTTP reques…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31981
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. A…
Bigfix Service Management
Mitigation only
HIGH 7.5
CVE-2025-55263
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re…
Aftermarket Cloud
Mitigation only