Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigfix Compliance MEDIUM 5.3
CVE-2023-37525

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain J…

Mitigation only
Fix from $1,600 2026-01-28
Aion CRITICAL 9.8
CVE-2025-55252

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting…

Mitigation only
Fix from $2,300 2026-01-19
Aion MEDIUM 5.3
CVE-2025-55250

HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in i…

No fix yet
Fix from $1,600 2026-01-19
Aion CRITICAL 9.8
CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Aion MEDIUM 5.3
CVE-2025-55249

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s over…

Mitigation only
Fix from $1,600 2026-01-19
Aion CRITICAL 9.8
CVE-2025-52660

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Aion HIGH 7.5
CVE-2025-52659

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, poten…

Mitigation only
Fix from $1,950 2026-01-19
Aion MEDIUM 5.3
CVE-2025-52661

HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in una…

Mitigation only
Fix from $1,600 2026-01-19
Myxalytics CRITICAL 9.8
CVE-2025-59870

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci…

Mitigation only
Fix from $2,300 2026-01-16
Dragon MEDIUM 5.5
CVE-2025-63401

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via m…

Fix: 7.6.0+
Fix from $1,600 2025-12-03
Dragon MEDIUM 5.5
CVE-2025-63402

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limit…

Fix: 7.6.0+
Fix from $1,600 2025-12-03
Unica HIGH 7.5
CVE-2025-51735

CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Mitigation only
Fix from $1,950 2025-11-28
Unica MEDIUM 6.3
CVE-2025-51736

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Unica MEDIUM 5.5
CVE-2025-51733

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Unica MEDIUM 5.4
CVE-2025-51734

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Connections MEDIUM 6.5
CVE-2025-52639

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are n…

Mitigation only
Fix from $1,600 2025-11-18
Traveler For Microsoft Outlook MEDIUM 5.5
CVE-2024-42192

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applicati…

Fix: 3.0.14+
Fix from $1,600 2025-10-16
Bigfix Mobile MEDIUM 6.1
CVE-2025-0277

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick us…

Fix: 3.4+
Fix from $1,600 2025-10-16
Bigfix Mobile MEDIUM 6.1
CVE-2025-0276

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An…

Fix: 3.4+
Fix from $1,600 2025-10-16
Unica HIGH 7.5
CVE-2025-31996

HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private …

Fix: 25.1.0.1+
Fix from $1,950 2025-10-13
Unica MEDIUM 5.3
CVE-2025-52615

HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the polici…

Fix: after 25.1.0
Fix from $1,600 2025-10-12
Unica MEDIUM 6.1
CVE-2025-31969

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers m…

Fix: after 25.1.0
Fix from $1,600 2025-10-12
Unica HIGH 7.5
CVE-2025-52616

HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnera…

No fix yet
Fix from $1,950 2025-10-12
Unica Centralized Offer Management CRITICAL 9.8
CVE-2025-31998

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use t…

Fix: 25.1.0.1+
Fix from $2,300 2025-10-12
Unica Centralized Offer Management HIGH 7.5
CVE-2025-31997

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access re…

Fix: 25.1.0.1+
Fix from $1,950 2025-10-12
Unica Centralized Offer Management CRITICAL 9.8
CVE-2025-31993

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input valida…

Fix: 25.1.0.1+
Fix from $2,300 2025-10-12
Aion CRITICAL 9.8
CVE-2025-52635

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

No fix yet
Fix from $2,300 2025-10-10
Aion HIGH 7.5
CVE-2025-52625

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers,…

Mitigation only
Fix from $1,950 2025-10-10
Aion MEDIUM 6.1
CVE-2025-52624

A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unaut…

Mitigation only
Fix from $1,600 2025-10-10
Aion HIGH 7.5
CVE-2025-52634

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10