Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-59868 1 Hcltech 1 Traveler For Microsoft Outlook 2026-07-06 N/A 5.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
CVE-2025-63402 1 Hcltech 1 Dragon 2026-07-05 N/A 5.5 MEDIUM
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
CVE-2025-63401 1 Hcltech 1 Dragon 2026-07-05 N/A 5.5 MEDIUM
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
CVE-2025-31978 1 Hcltech 1 Bigfix Service Management 2026-06-29 N/A 4.6 MEDIUM
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.
CVE-2025-31976 1 Hcltech 1 Bigfix Service Management 2026-06-29 N/A 4.8 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .
CVE-2025-59872 1 Hcltech 1 Zie For Web 2026-06-26 N/A 4.3 MEDIUM
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2025-62340 1 Hcltech 1 Icontrol 2026-06-26 N/A 3.1 LOW
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVE-2026-21791 1 Hcltech 1 Sametime 2026-06-17 N/A 3.3 LOW
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL
CVE-2026-21788 1 Hcltech 1 Connections 2026-06-17 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
CVE-2026-21786 1 Hcltech 1 Sametime 2026-06-17 N/A 3.3 LOW
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
CVE-2026-21783 1 Hcltech 1 Traveler 2026-06-17 N/A 4.3 MEDIUM
HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
CVE-2026-21767 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 4.0 MEDIUM
HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.
CVE-2026-21765 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 8.8 HIGH
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
CVE-2025-62326 1 Hcltech 1 Digital Experience 2026-06-17 N/A 6.1 MEDIUM
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
CVE-2025-62320 1 Hcltech 9 Unica, Unica Audience Central, Unica Campaign and 6 more 2026-06-17 N/A 4.7 MEDIUM
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
CVE-2025-62319 1 Hcltech 2 Unica, Unica Audience Central 2026-06-17 N/A 9.8 CRITICAL
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.
CVE-2025-59870 1 Hcltech 1 Myxalytics 2026-06-17 N/A 7.4 HIGH
HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
CVE-2025-59854 1 Hcltech 1 Dfxanalytics 2026-06-17 N/A 3.1 LOW
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP).
CVE-2025-59853 1 Hcltech 1 Dfxanalytics 2026-06-17 N/A 3.1 LOW
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.
CVE-2025-59852 1 Hcltech 1 Dfxanalytics 2026-06-17 N/A 3.7 LOW
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.