Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-21825
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute a…
Digital Experience Compose
Mitigation only
MEDIUM 6.1
CVE-2026-21826
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header …
Digital Experience Compose
Mitigation only
HIGH 8.8
CVE-2025-52612
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was c…
Icontrol
Mitigation only
MEDIUM 5.3
CVE-2025-52609
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS fi…
Icontrol
Mitigation only
CRITICAL 9.8
CVE-2025-31973
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images …
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31985
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-15633
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (…
Bigfix Webui Api
14 / 22+
HIGH 8.3
CVE-2024-30151
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz…
Bigfix Service Management
Mitigation only
HIGH 7.2
CVE-2025-31974
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31960
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed …
Bigfix Service Management
Mitigation only
HIGH 8.8
CVE-2025-52613
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e…
Bigfix Service Management
Mitigation only
MEDIUM 5.4
CVE-2025-31984
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…
Bigfix Service Management
Mitigation only
HIGH 7.5
CVE-2025-31976
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…
Bigfix Service Management
Mitigation only
MEDIUM 6.5
CVE-2025-31982
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…
Bigfix Service Management
Mitigation only
MEDIUM 5.7
CVE-2025-31957
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exp…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31975
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s…
Bigfix Service Management
Mitigation only
CRITICAL 9.8
CVE-2025-59851
HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-componen…
Dfxanalytics
4.1+
CRITICAL 9.1
CVE-2025-59852
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt…
Dfxanalytics
4.1+
MEDIUM 6.1
CVE-2025-59854
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection …
Dfxanalytics
4.1+
MEDIUM 5.3
CVE-2025-59853
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which coul…
Dfxanalytics
4.1+
MEDIUM 6.1
CVE-2025-31970
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict dire…
Dfxanalytics
4.1+
HIGH 8.2
CVE-2025-31958
HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route HTTP reques…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-31981
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. A…
Bigfix Service Management
Mitigation only
MEDIUM 5.3
CVE-2025-52641
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such inf…
Aion
2.1.2+
CRITICAL 9.8
CVE-2025-31991
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsu…
Devops Velocity
5.1.7+
HIGH 7.8
CVE-2026-21765
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host mach…
Bigfix Platform
after 11.0.5
HIGH 7.5
CVE-2025-55263
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re…
Aftermarket Cloud
Mitigation only
MEDIUM 5.5
CVE-2025-55264
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintai…
Aftermarket Cloud
Mitigation only
CRITICAL 9.8
CVE-2025-55261
HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…
Aftermarket Cloud
Mitigation only
HIGH 7.5
CVE-2025-55262
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…
Aftermarket Cloud
Mitigation only