Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icontrol MEDIUM 6.5
CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TL…

No fix yet
Fix from $1,600 2026-08-03
Icontrol MEDIUM 5.3
CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…

No fix yet
Fix from $1,600 2026-08-03
Icontrol MEDIUM 5.3
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…

No fix yet
Fix from $1,600 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56571

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa…

No fix yet
Fix from $1,600 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56568

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra…

No fix yet
Fix from $1,600 2026-07-31
Dryice Mycloud MEDIUM 6.5
CVE-2026-56577

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

No fix yet
Fix from $1,600 2026-07-21
Intelliops Event Management MEDIUM 5.3
CVE-2026-56584

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vu…

No fix yet
Fix from $1,600 2026-07-21
Devops Plan HIGH 7.5
CVE-2023-37507

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

Fix: 3.0.5+
Fix from $1,950 2026-07-21
Devops Plan MEDIUM 6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain brows…

Fix: 3.0.5+
Fix from $1,600 2026-07-21
Devops Loop MEDIUM 5.3
CVE-2026-21762

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attack…

No fix yet
Fix from $1,600 2026-07-17
Devops Loop MEDIUM 5.4
CVE-2026-21761

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-orig…

No fix yet
Fix from $1,600 2026-07-17
Dfxanalytics CRITICAL 9.8
CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents o…

Fix: after 3.0
Fix from $2,300 2026-07-16
Dfxanalytics HIGH 7.5
CVE-2026-56454

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cr…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics HIGH 7.5
CVE-2026-56455

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validat…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics MEDIUM 5.3
CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information r…

Fix: after 3.0
Fix from $1,600 2026-07-16
Dfxanalytics HIGH 8.2
CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its gene…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics HIGH 7.2
CVE-2026-35140

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure"…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics MEDIUM 6.5
CVE-2026-35143

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies …

Fix: after 3.0
Fix from $1,600 2026-07-16
Dfxanalytics MEDIUM 5.3
CVE-2026-35141

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently re…

Fix: after 3.0
Fix from $1,600 2026-07-16
Dfx Server HIGH 8.2
CVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication s…

Fix: after 2.5
Fix from $1,950 2026-07-16
Dfx Server HIGH 8.2
CVE-2026-35149

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials …

Fix: after 2.5
Fix from $1,950 2026-07-16
Dfx Server MEDIUM 6.3
CVE-2026-35146

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted chan…

Fix: after 2.5
Fix from $1,600 2026-07-16
Dfx Server MEDIUM 6.3
CVE-2026-35148

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form…

Fix: after 2.5
Fix from $1,600 2026-07-16
Traveler For Microsoft Outlook MEDIUM 5.5
CVE-2025-59868

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit applicat…

Fix: 3.0.15+
Fix from $1,600 2026-06-27
Traveler For Microsoft Outlook HIGH 7.8
CVE-2023-37524

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5…

Fix: 3.0.6+
Fix from $1,950 2026-06-27
Traveler For Microsoft Outlook HIGH 7.8
CVE-2024-23581

The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.

Fix: 3.0.9+
Fix from $1,950 2026-06-26
Zie For Web CRITICAL 9.8
CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obt…

Mitigation only
Fix from $2,300 2026-06-17
Icontrol MEDIUM 5.3
CVE-2025-62340

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to au…

Mitigation only
Fix from $1,600 2026-06-17
Devops Plan MEDIUM 6.1
CVE-2026-4096

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could al…

Fix: 3.0.7+
Fix from $1,600 2026-06-11
Digital Experience HIGH 8.8
CVE-2026-21837

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary o…

Mitigation only
Fix from $1,950 2026-06-05