← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Hcl Leap
Jun 17, 2026
Apr 24, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
1Hcltech
1Hcl Leap
Jun 17, 2026
Apr 24, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
1Hcltech
1Hcl Leap
Jun 17, 2026
Apr 24, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
1Hcltech
1Hcl Leap
Jun 17, 2026
Apr 24, 2025
N/A· v4
4.1 MEDIUM· v3
N/A· v2
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Apr 17, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unau...Show more
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.Show less
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Apr 17, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or in...Show more
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
Apr 15, 2025
2.1 LOW· v4
8.1 HIGH· v3
N/A· v2
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as...Show more
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
Apr 15, 2025
4.8 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
1Hcltech
1Bigfix Platform
Jun 17, 2026
Apr 15, 2025
5.6 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
1Hcltech
1Connections
Jun 17, 2026
Apr 4, 2025
N/A· v4
3.5 LOW· v3
N/A· v2
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
1Hcltech
1Traveler
Jun 17, 2026
Apr 3, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could ex...Show more
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.Show less
1Hcltech
1Traveler
Jun 17, 2026
Apr 3, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
1Hcltech
1Hcl Sx
Jun 17, 2026
Mar 26, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Mar 19, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain acces...Show more
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.Show less
1Hcltech
1Hcl Sx
Jun 17, 2026
Mar 3, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
1Hcltech
1Dryice Mycloud
Jun 17, 2026
Feb 25, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Servi...Show more
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.Show less
1Hcltech
1Connections Docs
Jun 17, 2026
Feb 12, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
1Hcltech
1Dryice Iautomate
Jun 17, 2026
Feb 5, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by...Show more
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.Show less
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attac...Show more
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.Show less