Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-59870
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci…
Myxalytics
Mitigation only
HIGH 7.5
CVE-2025-51735
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Unica
Mitigation only
MEDIUM 6.3
CVE-2025-51736
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Unica
No fix yet
MEDIUM 5.5
CVE-2025-51733
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Unica
No fix yet
MEDIUM 5.4
CVE-2025-51734
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Unica
No fix yet
MEDIUM 6.5
CVE-2025-52639
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are n…
Connections
Mitigation only
HIGH 7.5
CVE-2025-52616
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnera…
Unica
No fix yet
CRITICAL 9.8
CVE-2025-52635
A
rusted types in scripts not enforced in CSP vulnerability has been identified
in HCL AION.This issue affects AION: 2.0.
Aion
No fix yet
HIGH 7.5
CVE-2025-52625
A vulnerability
Cacheable SSL Page Found vulnerability has been identified
in HCL AION.
Cached data may expose credentials, system identifiers,…
Aion
Mitigation only
MEDIUM 6.1
CVE-2025-52624
A vulnerability Bypass of the script allowlist configuration in HCL AION.
An incorrectly configured Content-Security-Policy header may allow unaut…
Aion
Mitigation only
HIGH 7.5
CVE-2025-52634
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
Aion
No fix yet
MEDIUM 6.1
CVE-2025-52650
Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
Aion
Mitigation only
HIGH 7.5
CVE-2025-52630
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Aion
No fix yet
HIGH 7.5
CVE-2025-52632
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
Aion
Mitigation only
HIGH 7.6
CVE-2025-52656
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application obje…
Dryice Myxalytics
Mitigation only
MEDIUM 5.4
CVE-2025-52653
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts…
Dryice Myxalytics
Mitigation only
MEDIUM 6.5
CVE-2025-31972
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an…
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31977
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit thi…
Bigfix Service Management
Mitigation only
HIGH 7.5
CVE-2025-31987
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
Connections Docs
Mitigation only
MEDIUM 5.7
CVE-2025-0251
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which …
Intelliops Event Management
Mitigation only
MEDIUM 5.9
CVE-2025-0249
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to acces…
Intelliops Event Management
Mitigation only
HIGH 7.1
CVE-2025-31952
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing…
Dryice Iautomate
Mitigation only
MEDIUM 6.5
CVE-2025-31953
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p…
Dryice Iautomate
Mitigation only
MEDIUM 6.5
CVE-2025-31955
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s…
Dryice Iautomate
No fix yet
MEDIUM 5.4
CVE-2024-42212
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a …
Bigfix Compliance
Mitigation only
MEDIUM 5.3
CVE-2024-42213
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files b…
Bigfix Compliance
Mitigation only
MEDIUM 5.4
CVE-2022-42450
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
Domino Leap
Mitigation only
CRITICAL 9.8
CVE-2024-30152
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, …
Hcl Sx
Mitigation only
HIGH 7.5
CVE-2024-42178
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con…
Dryice Myxalytics
Mitigation only
MEDIUM 6.4
CVE-2024-42177
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to i…
Dryice Myxalytics
Mitigation only