Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aftermarket Cloud HIGH 8.1
CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or imper…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 6.5
CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available a…

No fix yet
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55269

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 8.8
CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55268

HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55267

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55265

HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud MEDIUM 6.5
CVE-2025-55266

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transactio…

Mitigation only
Fix from $1,600 2026-03-26
Connections MEDIUM 5.4
CVE-2026-21788

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Mitigation only
Fix from $1,600 2026-03-19
Unica MEDIUM 5.4
CVE-2024-42210

A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known …

Fix: 12.1.9+
Fix from $1,600 2026-03-19
Unica MEDIUM 6.1
CVE-2025-62320

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Becau…

Fix: 12.1.11 / 25.1.1.0.1+
Fix from $1,600 2026-03-17
Unica CRITICAL 9.8
CVE-2025-62319

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE…

Fix: 25.1.1.0.1+
Fix from $2,300 2026-03-16
Aion MEDIUM 5.3
CVE-2025-52649

HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infe…

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Aion HIGH 8.2
CVE-2025-52644

HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms ma…

Fix: 2.1.2+
Fix from $1,950 2026-03-16
Aion HIGH 7.8
CVE-2025-52643

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This…

Fix: 2.1.2+
Fix from $1,950 2026-03-16
Aion MEDIUM 6.5
CVE-2025-52642

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of…

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Aion MEDIUM 5.3
CVE-2025-52645

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This …

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Aion MEDIUM 5.3
CVE-2025-52646

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper valid…

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Aion HIGH 7.5
CVE-2025-52636

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow exces…

Fix: 2.1.2+
Fix from $1,950 2026-03-16
Devops Plan HIGH 7.5
CVE-2025-36363

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Fix: 3.0.6+
Fix from $1,950 2026-03-03
Aion HIGH 8.8
CVE-2025-52628

HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site request…

Mitigation only
Fix from $1,950 2026-02-03
Aion HIGH 8.1
CVE-2025-52631

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potent…

Mitigation only
Fix from $1,950 2026-02-03
Aion MEDIUM 6.5
CVE-2025-52623

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields…

Mitigation only
Fix from $1,600 2026-02-03
Aion MEDIUM 5.3
CVE-2025-52633

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent…

Mitigation only
Fix from $1,600 2026-02-03
Aion HIGH 7.5
CVE-2025-52627

Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially …

Mitigation only
Fix from $1,950 2026-02-03
Aion MEDIUM 6.1
CVE-2025-52629

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other …

Mitigation only
Fix from $1,600 2026-02-03
Aion CRITICAL 9.8
CVE-2025-52626

A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio…

Mitigation only
Fix from $2,300 2026-02-03