Total
395841 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-42195 | 1 Hcltechsw | 2 Hcl Devops Deploy, Hcl Launch | 2026-06-17 | N/A | 3.1 LOW |
| HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | |||||
| CVE-2024-42194 | 2026-06-17 | N/A | 3.1 LOW | ||
| An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call. | |||||
| CVE-2024-42193 | 1 Hcltech | 1 Bigfix Platform | 2026-06-17 | N/A | 8.1 HIGH |
| HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access. | |||||
| CVE-2024-42192 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-06-17 | N/A | 5.5 MEDIUM |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | |||||
| CVE-2024-42191 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-06-17 | N/A | 6.5 MEDIUM |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |||||
| CVE-2024-42190 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-06-17 | N/A | 6.5 MEDIUM |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |||||
| CVE-2024-42189 | 1 Hcltech | 1 Bigfix Platform | 2026-06-17 | N/A | 6.5 MEDIUM |
| HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter. | |||||
| CVE-2024-42188 | 1 Hcltech | 1 Connections | 2026-06-17 | N/A | 3.7 LOW |
| HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios. | |||||
| CVE-2024-42187 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable to path traversal attacks. | |||||
| CVE-2024-42186 | 2026-06-17 | N/A | 2.8 LOW | ||
| BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation. | |||||
| CVE-2024-42185 | 2026-06-17 | N/A | 2.5 LOW | ||
| BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access. | |||||
| CVE-2024-42184 | 2026-06-17 | N/A | 2.5 LOW | ||
| BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme. | |||||
| CVE-2024-42183 | 2026-06-17 | N/A | 2.5 LOW | ||
| BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls. | |||||
| CVE-2024-42182 | 2026-06-17 | N/A | 2.5 LOW | ||
| BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost. | |||||
| CVE-2024-42181 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 1.6 LOW |
| HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | |||||
| CVE-2024-42180 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 1.6 LOW |
| HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files. | |||||
| CVE-2024-42179 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 2.0 LOW |
| HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version. | |||||
| CVE-2024-42178 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 2.5 LOW |
| HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution. | |||||
| CVE-2024-42177 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 2.6 LOW |
| HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system. | |||||
| CVE-2024-42176 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 2.6 LOW |
| HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information. | |||||
