Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Compose MEDIUM 6.1
CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute a…

Mitigation only
Fix from $1,600 2026-06-05
Digital Experience Compose MEDIUM 6.1
CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header …

Mitigation only
Fix from $1,600 2026-06-05
Icontrol HIGH 8.8
CVE-2025-52612

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was c…

Mitigation only
Fix from $1,950 2026-06-04
Icontrol MEDIUM 5.3
CVE-2025-52609

HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS fi…

Mitigation only
Fix from $1,600 2026-06-04
Bigfix Service Management CRITICAL 9.8
CVE-2025-31973

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images …

Mitigation only
Fix from $2,300 2026-05-20
Bigfix Service Management MEDIUM 6.5
CVE-2025-31985

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…

Mitigation only
Fix from $1,600 2026-05-20
Bigfix Webui Api MEDIUM 6.5
CVE-2025-15633

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (…

Fix: 14 / 22+
Fix from $1,600 2026-05-09
Bigfix Service Management HIGH 8.3
CVE-2024-30151

HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management HIGH 7.2
CVE-2025-31974

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management MEDIUM 5.3
CVE-2025-31960

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed …

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management HIGH 8.8
CVE-2025-52613

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management MEDIUM 5.4
CVE-2025-31984

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management HIGH 7.5
CVE-2025-31976

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management MEDIUM 6.5
CVE-2025-31982

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management MEDIUM 5.7
CVE-2025-31957

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exp…

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management MEDIUM 5.3
CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s…

Mitigation only
Fix from $1,600 2026-05-06
Dfxanalytics CRITICAL 9.8
CVE-2025-59851

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-componen…

Fix: 4.1+
Fix from $2,300 2026-05-06
Dfxanalytics CRITICAL 9.1
CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt…

Fix: 4.1+
Fix from $2,300 2026-05-06
Dfxanalytics MEDIUM 6.1
CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection …

Fix: 4.1+
Fix from $1,600 2026-05-06
Dfxanalytics MEDIUM 5.3
CVE-2025-59853

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which coul…

Fix: 4.1+
Fix from $1,600 2026-05-06
Dfxanalytics MEDIUM 6.1
CVE-2025-31970

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict dire…

Fix: 4.1+
Fix from $1,600 2026-05-06
Bigfix Service Management HIGH 8.2
CVE-2025-31958

HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP reques…

Mitigation only
Fix from $1,950 2026-04-21
Bigfix Service Management MEDIUM 5.3
CVE-2025-31981

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  A…

Mitigation only
Fix from $1,600 2026-04-21
Aion MEDIUM 5.3
CVE-2025-52641

HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such inf…

Fix: 2.1.2+
Fix from $1,600 2026-04-15
Devops Velocity CRITICAL 9.8
CVE-2025-31991

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsu…

Fix: 5.1.7+
Fix from $2,300 2026-04-13
Bigfix Platform HIGH 7.8
CVE-2026-21765

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host mach…

Fix: after 11.0.5
Fix from $1,950 2026-04-02
Aftermarket Cloud HIGH 7.5
CVE-2025-55263

HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 5.5
CVE-2025-55264

HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintai…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55261

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55262

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…

Mitigation only
Fix from $1,950 2026-03-26