Vulnerabilities (CVE)

Total 395841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42195 1 Hcltechsw 2 Hcl Devops Deploy, Hcl Launch 2026-06-17 N/A 3.1 LOW
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
CVE-2024-42194 2026-06-17 N/A 3.1 LOW
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.
CVE-2024-42193 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 8.1 HIGH
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
CVE-2024-42192 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 5.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
CVE-2024-42191 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 6.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
CVE-2024-42190 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 6.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
CVE-2024-42189 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
CVE-2024-42188 1 Hcltech 1 Connections 2026-06-17 N/A 3.7 LOW
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
CVE-2024-42187 2026-06-17 N/A 5.3 MEDIUM
BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable to path traversal attacks.
CVE-2024-42186 2026-06-17 N/A 2.8 LOW
BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.
CVE-2024-42185 2026-06-17 N/A 2.5 LOW
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.
CVE-2024-42184 2026-06-17 N/A 2.5 LOW
BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme.
CVE-2024-42183 2026-06-17 N/A 2.5 LOW
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls.
CVE-2024-42182 2026-06-17 N/A 2.5 LOW
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost.
CVE-2024-42181 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 1.6 LOW
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVE-2024-42180 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 1.6 LOW
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
CVE-2024-42179 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.0 LOW
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.
CVE-2024-42178 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.5 LOW
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.
CVE-2024-42177 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.6 LOW
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system.
CVE-2024-42176 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.6 LOW
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.