| HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive… CVE-2026-67106 | Severity medium |
| HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network… CVE-2026-67105 | Severity high |
| HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to… CVE-2026-67104 | Severity medium |
| HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to… CVE-2026-56599 | Severity low |
| HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and… CVE-2026-56589 | Severity high |
| HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application… CVE-2025-62340 | Severity medium |
| HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be… CVE-2025-59872 | Severity critical |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to… CVE-2025-59868 | Severity medium |
| HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated… CVE-2025-59854 | Severity medium |
| HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses… CVE-2025-59853 | Severity medium |
| HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network… CVE-2025-59852 | Severity critical |
| HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or… CVE-2025-59851 | Severity critical |
| HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of… CVE-2025-52653 | Severity medium |
| HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure… CVE-2025-52641 | Severity medium |
| HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI… CVE-2025-52613 | Severity high |
| HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can… CVE-2025-31998 | Severity critical |
| Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks… CVE-2025-31991 | Severity critical |
| HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header… CVE-2025-31984 | Severity medium |
| HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers… CVE-2025-31983 | Severity medium |
| HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could… CVE-2025-31982 | Severity medium |
| HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted… CVE-2025-31981 | Severity medium |
| HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or… CVE-2025-31978 | Severity medium |
| HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could… CVE-2025-31977 | Severity medium |
| HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a… CVE-2025-31976 | Severity high |
| HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners… CVE-2025-31975 | Severity medium |
| HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system… CVE-2025-31974 | Severity high |
| HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which… CVE-2025-31972 | Severity medium |
| HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define… CVE-2025-31970 | Severity medium |
| Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact… CVE-2025-31964 | Severity medium |
| Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local… CVE-2025-31963 | Severity low |
| Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to… CVE-2025-31962 | Severity medium |
| HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was… CVE-2025-31960 | Severity medium |
| HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and… CVE-2025-31959 | Severity low |
| HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route… CVE-2025-31958 | Severity high |
| HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized… CVE-2025-31957 | Severity medium |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or… CVE-2024-42192 | Severity medium |
| The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. CVE-2024-23581 | Severity high |
| HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if… CVE-2023-37508 | Severity medium |
| HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information… CVE-2023-37507 | Severity high |