Filtered by vendor Hcltech
Subscribe
Total
455 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-56537 | 1 Hcltech | 1 Connections | 2026-08-20 | N/A | 3.5 LOW |
| HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data. | |||||
| CVE-2026-56538 | 1 Hcltech | 1 Connections | 2026-08-20 | N/A | 3.5 LOW |
| An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. | |||||
| CVE-2026-21764 | 1 Hcltech | 1 Devops Loop | 2026-08-13 | N/A | 3.1 LOW |
| HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions. | |||||
| CVE-2026-21760 | 1 Hcltech | 1 Devops Loop | 2026-08-13 | N/A | 4.6 MEDIUM |
| HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | |||||
| CVE-2026-21761 | 1 Hcltech | 1 Devops Loop | 2026-08-13 | N/A | 4.2 MEDIUM |
| HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. | |||||
| CVE-2026-21762 | 1 Hcltech | 1 Devops Loop | 2026-08-13 | N/A | 3.7 LOW |
| HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting. | |||||
| CVE-2026-56568 | 1 Hcltech | 1 Icontrol | 2026-08-06 | N/A | 3.7 LOW |
| HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status | |||||
| CVE-2026-56567 | 1 Hcltech | 1 Icontrol | 2026-08-06 | N/A | 5.1 MEDIUM |
| HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |||||
| CVE-2026-56609 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 4.8 MEDIUM |
| HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. | |||||
| CVE-2026-56608 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 3.7 LOW |
| HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization. | |||||
| CVE-2026-56571 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 3.7 LOW |
| HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated. | |||||
| CVE-2026-56570 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 3.7 LOW |
| HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. | |||||
| CVE-2026-56569 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 4.0 MEDIUM |
| HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |||||
| CVE-2026-56583 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse. | |||||
| CVE-2026-56580 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.2 LOW |
| HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system. | |||||
| CVE-2026-56577 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | |||||
| CVE-2026-56579 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security. | |||||
| CVE-2026-56581 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.6 LOW |
| HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens. | |||||
| CVE-2026-56578 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.2 LOW |
| HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions. | |||||
| CVE-2026-56582 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. | |||||
