Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aion MEDIUM 6.1
CVE-2025-52650

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Mitigation only
Fix from $1,600 2025-10-10
Aion HIGH 7.5
CVE-2025-52630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10
Aion HIGH 7.5
CVE-2025-52632

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Mitigation only
Fix from $1,950 2025-10-10
Dryice Myxalytics HIGH 7.6
CVE-2025-52656

HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application obje…

Mitigation only
Fix from $1,950 2025-10-03
Dryice Myxalytics MEDIUM 5.4
CVE-2025-52653

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts…

Mitigation only
Fix from $1,600 2025-10-03
Bigfix Service Management MEDIUM 6.5
CVE-2025-31972

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an…

Mitigation only
Fix from $1,600 2025-08-28
Bigfix Service Management MEDIUM 6.5
CVE-2025-31977

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit thi…

Mitigation only
Fix from $1,600 2025-08-28
Bigfix Saas CRITICAL 9.8
CVE-2025-52618

HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL …

Fix: 8.1.14+
Fix from $2,300 2025-08-15
Bigfix Saas HIGH 7.5
CVE-2025-52621

HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin heade…

Fix: 8.1.14+
Fix from $1,950 2025-08-15
Bigfix Saas MEDIUM 5.4
CVE-2025-52620

HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately valida…

Fix: 8.1.14+
Fix from $1,600 2025-08-15
Bigfix Saas MEDIUM 5.3
CVE-2025-52619

HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitiv…

Fix: 8.1.14+
Fix from $1,600 2025-08-15
Connections Docs HIGH 7.5
CVE-2025-31987

HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

Mitigation only
Fix from $1,950 2025-08-14
Intelliops Event Management MEDIUM 5.7
CVE-2025-0251

HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the same user credentials, which …

Mitigation only
Fix from $1,600 2025-07-25
Intelliops Event Management MEDIUM 5.9
CVE-2025-0249

HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to acces…

Mitigation only
Fix from $1,600 2025-07-25
Dryice Iautomate HIGH 7.1
CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing…

Mitigation only
Fix from $1,950 2025-07-24
Dryice Iautomate MEDIUM 6.5
CVE-2025-31953

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p…

Mitigation only
Fix from $1,600 2025-07-24
Dryice Iautomate MEDIUM 6.5
CVE-2025-31955

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s…

No fix yet
Fix from $1,600 2025-07-24
Traveler For Microsoft Outlook CRITICAL 9.8
CVE-2024-42190

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the appl…

Fix: 3.0.12+
Fix from $2,300 2025-05-30
Traveler For Microsoft Outlook CRITICAL 9.8
CVE-2024-42191

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the appl…

Fix: 3.0.12+
Fix from $2,300 2025-05-30
Bigfix Compliance MEDIUM 5.4
CVE-2024-42212

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a …

Mitigation only
Fix from $1,600 2025-05-05
Bigfix Compliance MEDIUM 5.3
CVE-2024-42213

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files b…

Mitigation only
Fix from $1,600 2025-05-05
Domino Leap MEDIUM 6.1
CVE-2023-37535

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

Fix: 1.1.3+
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 6.1
CVE-2024-30145

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

Fix: 1.1.5+
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 5.4
CVE-2024-30115

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Fix: 1.1.4+
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 5.3
CVE-2023-45721

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Fix: 1.1.4+
Fix from $1,600 2025-04-30
Domino Leap HIGH 7.5
CVE-2023-37517

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Fix: 1.1.2+
Fix from $1,950 2025-04-30
Domino Leap MEDIUM 5.4
CVE-2022-42450

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

Mitigation only
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 5.4
CVE-2022-42449

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

Fix: 1.1.1+
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 5.4
CVE-2022-27562

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

Fix: 1.1.1+
Fix from $1,600 2025-04-30
Hcl Sx CRITICAL 9.8
CVE-2024-30152

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, …

Mitigation only
Fix from $2,300 2025-04-25