Hcltech Security Vulnerabilities (CVEs)
Track 99 security vulnerabilities affecting Hcltech products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
HCL Connections has an information disclosure vulnerability where, in specific user navigation scenarios, limited internal metadata can be exposed in ...
Feb 20, 2026HCL AION 2.0 has a vulnerability where password fields don't disable autocomplete, potentially allowing browsers to store or autofill credentials. Thi...
Feb 3, 2026HCL AION versions 2.0 have a SameSite cookie vulnerability that allows cookies to be sent in cross-site requests. This increases exposure to cross-sit...
Feb 3, 2026HCL AION 2.0 lacks proper HTTP Strict-Transport-Security headers, allowing attackers to force insecure HTTP connections or downgrade HTTPS to HTTP. Th...
Feb 3, 2026HCL AION stores sensitive session information in persistent cookies that survive browser sessions, potentially allowing attackers to hijack user sessi...
Feb 3, 2026This vulnerability in HCL BigFix Compliance allows remote attackers to access sensitive files in the WEB-INF directory, potentially exposing Java clas...
Jan 28, 2026HCL AION version 2 contains a technical error disclosure vulnerability that can expose sensitive system details through error messages. This affects o...
Jan 19, 2026HCL AION version 2 has a weak password policy vulnerability that allows users to set easily guessable passwords. This could enable attackers to gain u...
Jan 19, 2026HCL AION web applications are vulnerable due to missing standard security HTTP response headers. This allows attackers to more easily conduct common w...
Jan 19, 2026HCL AION has an unrestricted file upload vulnerability that allows attackers to upload malicious files to the server. This could lead to remote code e...
Jan 19, 2026HCL AION version 2 has a cacheable HTTP response vulnerability where sensitive or dynamic content may be stored in caches. This could allow unauthoriz...
Jan 19, 2026HCL AION has an unrestricted file upload vulnerability that allows attackers to upload malicious files. This could lead to remote code execution or sy...
Jan 19, 2026HCL AION version 2 has JWT tokens that remain valid for an excessively long time, allowing attackers who obtain these tokens to potentially maintain u...
Jan 19, 2026HCL MyXalytics uses a static JWT signing secret that never rotates, allowing attackers who obtain the secret to forge authentication tokens. This affe...
Jan 16, 2026This vulnerability allows authenticated attackers to maintain unauthorized access to protected API endpoints in HCL BigFix IVR due to insufficient ses...
Jan 7, 2026This vulnerability allows a local attacker to make unauthorized configuration changes to HCL BigFix IVR without authentication. It affects systems run...
Jan 7, 2026This vulnerability in HCL BigFix IVR 4.2 allows privileged attackers to disrupt service availability by exploiting administrative services bound to ex...
Jan 7, 2026A Cross-Site Scripting (XSS) vulnerability in HCLTech DRAGON allows remote attackers to inject malicious scripts into web pages viewed by other users....
Dec 3, 2025This vulnerability in HCLTech GRAGON allows remote attackers to execute arbitrary code by exploiting APIs that lack proper request size or number limi...
Dec 3, 2025A Cross-Site Request Forgery (CSRF) vulnerability in HCL Unica 12.0.0 allows attackers to trick authenticated users into performing unintended actions...
Nov 28, 2025A cross-site scripting (XSS) vulnerability in HCL Unica 12.0.0 allows attackers to inject malicious scripts into web pages viewed by other users. This...
Nov 28, 2025This CSV formula injection vulnerability in HCL Unica 12.0.0 allows attackers to execute arbitrary formulas when CSV files are opened in spreadsheet a...
Nov 28, 2025This CVE describes a file upload vulnerability in HCL Unica 12.0.0 that allows attackers to upload malicious files to the server. The vulnerability af...
Nov 28, 2025HCL Connections has an information disclosure vulnerability where improper rendering of application data allows authenticated users to access sensitiv...
Nov 18, 2025HCL Traveler for Microsoft Outlook (HTMO) has a credential leakage vulnerability that could allow attackers to access other computers or applications ...
Oct 16, 2025HCL BigFix Mobile 3.3 and earlier have an insecure Content Security Policy (CSP) that doesn't properly restrict script sources. This allows attackers ...
Oct 16, 2025HCL BigFix Modern Client Management (MCM) versions 3.3 and earlier have an insecure Content Security Policy (CSP) that doesn't properly restrict scrip...
Oct 16, 2025HCL BigFix Mobile versions 3.3 and earlier have an improper access control vulnerability that allows unauthorized users to access a limited set of end...
Oct 16, 2025CVE-2025-0274 is an improper access control vulnerability in HCL BigFix Modern Client Management (MCM) that allows unauthorized users to access a limi...
Oct 16, 2025HCL Unica Platform has improper access controls that leave files unprotected, potentially exposing sensitive system or private information. Attackers ...
Oct 13, 2025HCL Unica Platform has a misconfigured Content Security Policy (CSP) that could allow attackers to load malicious resources in users' browsers. This c...
Oct 12, 2025HCL Unica 12.1.10 exposes sensitive system information that could help attackers plan targeted attacks. This affects organizations using HCL Unica 12....
Oct 12, 2025HCL Unica Centralized Offer Management has an Insecure Direct Object Reference (IDOR) vulnerability that allows attackers to bypass authorization and ...
Oct 12, 2025This vulnerability allows attackers to bypass script allowlist configurations in HCL AION due to an incorrectly configured Content-Security-Policy hea...
Oct 10, 2025This vulnerability allows inline script execution despite Content Security Policy (CSP) restrictions in HCL AION v2.0. Attackers can bypass CSP protec...
Oct 10, 2025A missing Secure attribute in SSL cookies in HCL AION allows attackers to intercept session cookies over unencrypted HTTP connections. This affects HC...
Oct 10, 2025HCL MyXalytics v6.6 has an HTML injection vulnerability where untrusted input isn't properly sanitized before being included in web output. This allow...
Oct 3, 2025CVE-2025-52656 is a mass assignment vulnerability in HCL MyXalytics 6.6 that allows attackers to modify sensitive application fields without proper au...
Oct 3, 2025HCL BigFix SM has a cryptographic weakness due to weak or outdated encryption algorithms, allowing attackers with network access to potentially decryp...
Aug 28, 2025HCL BigFix SaaS Authentication Service contains a SQL injection vulnerability that allows attackers to manipulate SQL queries. This affects organizati...
Aug 15, 2025HCL BigFix SaaS Authentication Service discloses sensitive version information through error messages under certain conditions. This information discl...
Aug 15, 2025HCL BigFix SaaS Authentication Service contains a Cross-Site Scripting vulnerability in its image upload functionality. Attackers can upload malicious...
Aug 15, 2025HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning due to improper validation of the Origin HTTP header. This could allow attacke...
Aug 15, 2025CVE-2025-31987 is a resource exhaustion vulnerability in HCL Connections Docs where improper validation of uploaded documents can lead to denial of se...
Aug 14, 2025HCL iAutomate has insufficient session expiration, allowing authentication tokens to remain valid indefinitely unless manually revoked. This affects a...
Jul 24, 2025HCL iAutomate has a sensitive data exposure vulnerability that allows unauthorized access to confidential information stored within the system. This a...
Jul 24, 2025HCL Traveler for Microsoft Outlook (HTMO) has a COM hijacking vulnerability that allows attackers to replace legitimate application components with ma...
May 30, 2025HCL BigFix Compliance leaves temporary files in production environments that attackers can access through predictable URLs or misconfigured permission...
May 5, 2025This vulnerability allows attackers to inject malicious scripts through query parameters in HCL Domino Volt and Domino Leap applications due to insuff...
Apr 30, 2025This vulnerability in HCL Leap allows attackers to inject malicious scripts into web applications through the HTML widget. The insufficient sanitizati...
Apr 30, 2025Why Monitor Hcltech Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 99+ known vulnerabilities affecting Hcltech products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Hcltech packages in under 60 seconds. No agents required - completely agentless scanning that works across Hcltech deployments.
Free vulnerability database: Access detailed information about every Hcltech CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Hcltech CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions