← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-base...Show more
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.Show less
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
1Hcltech
1Aion
Jun 17, 2026
Jan 19, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.
1Hcltech
1Myxalytics
Jun 17, 2026
Jan 16, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
1Hcltech
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Jan 7, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external ne...Show more
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.Show less
1Hcltech
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Jan 7, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administr...Show more
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.Show less
1Hcltech
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Jan 7, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expi...Show more
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.Show less
1Hcltech
1Dragon
Jul 5, 2026
Dec 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
1Hcltech
1Dragon
Jul 5, 2026
Dec 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
1Hcltech
1Unica
Jun 17, 2026
Nov 28, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
1Hcltech
1Unica
Jun 17, 2026
Nov 28, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
1Hcltech
1Unica
Jun 17, 2026
Nov 28, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
1Hcltech
1Unica
Jun 17, 2026
Nov 28, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
1Hcltech
1Connections
Jun 17, 2026
Nov 18, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.
1Hcltech
1Dryice Iautomate
Jun 17, 2026
Nov 5, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker...Show more
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.Show less
1Hcltech
1Traveler For Microsoft Outlook
Jun 17, 2026
Oct 16, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
1Hcltech
2Bigfix Mobile
Bigfix Modern Client Management
Jun 17, 2026
Oct 16, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of...Show more
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.Show less