Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-21825 HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute a… Digital Experience Compose Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-21826 HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header … Digital Experience Compose Mitigation only Fix from $1,6002026-06-05 HIGH 8.8 CVE-2025-52612 HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was c… Icontrol Mitigation only Fix from $1,9502026-06-04 MEDIUM 5.3 CVE-2025-52609 HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS fi… Icontrol Mitigation only Fix from $1,6002026-06-04 CRITICAL 9.8 CVE-2025-31973 HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images … Bigfix Service Management Mitigation only Fix from $2,3002026-05-20 MEDIUM 6.5 CVE-2025-31985 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou… Bigfix Service Management Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.5 CVE-2025-15633 An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (… Bigfix Webui Api 14 / 22+ Fix from $1,6002026-05-09 HIGH 8.3 CVE-2024-30151 HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 HIGH 7.2 CVE-2025-31974 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.3 CVE-2025-31960 HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed … Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 HIGH 8.8 CVE-2025-52613 HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.4 CVE-2025-31984 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 HIGH 7.5 CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2025-31982 HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.7 CVE-2025-31957 HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exp… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2025-31975 HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 CRITICAL 9.8 CVE-2025-59851 HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-componen… Dfxanalytics 4.1+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2025-59852 HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt… Dfxanalytics 4.1+ Fix from $2,3002026-05-06 MEDIUM 6.1 CVE-2025-59854 HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection … Dfxanalytics 4.1+ Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2025-59853 HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which coul… Dfxanalytics 4.1+ Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2025-31970 HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict dire… Dfxanalytics 4.1+ Fix from $1,6002026-05-06 HIGH 8.2 CVE-2025-31958 HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP reques… Bigfix Service Management Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.3 CVE-2025-31981 HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  A… Bigfix Service Management Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2025-52641 HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such inf… Aion 2.1.2+ Fix from $1,6002026-04-15 CRITICAL 9.8 CVE-2025-31991 Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsu… Devops Velocity 5.1.7+ Fix from $2,3002026-04-13 HIGH 7.8 CVE-2026-21765 HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host mach… Bigfix Platform after 11.0.5 Fix from $1,9502026-04-02 HIGH 7.5 CVE-2025-55263 HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26 MEDIUM 5.5 CVE-2025-55264 HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintai… Aftermarket Cloud Mitigation only Fix from $1,6002026-03-26 CRITICAL 9.8 CVE-2025-55261 HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 HIGH 7.5 CVE-2025-55262 HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26