Hcltech Security Vulnerabilities (CVEs)
Track 100 security vulnerabilities affecting Hcltech products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows certain administrative users in HCL Domino Leap to import applications from the server's filesystem due to improper access c...
Apr 30, 2025CVE-2022-27562 is an unsafe file upload vulnerability in HCL Domino Volt that allows attackers to upload .html files containing malicious JavaScript. ...
Apr 30, 2025This vulnerability in HCL Leap allows attackers to inject malicious scripts into SVG files, which then execute in users' browsers when viewing affecte...
Apr 24, 2025This CVE describes a cross-site scripting (XSS) vulnerability in HCL Leap that allows attackers to inject malicious scripts into both the authoring en...
Apr 24, 2025This vulnerability in HCL Leap allows attackers to inject malicious scripts into web applications through the HTML widget. It affects organizations us...
Apr 24, 2025This vulnerability in HCL Leap allows attackers to inject malicious scripts through query parameters due to insufficient URI protocol whitelisting. Th...
Apr 24, 2025HCL BigFix Web Reports has improper SSL certificate validation, allowing man-in-the-middle attacks. Attackers could intercept and manipulate HTTPS com...
Apr 15, 2025HCL BigFix Web Reports has a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages. When users vi...
Apr 15, 2025HCL Traveler for Windows exposes internal file paths in error messages or debug logs, potentially revealing sensitive directory structures. This affec...
Apr 3, 2025HCL SX fails to set the secure attribute on authorization tokens and session cookies, allowing attackers to potentially steal these cookies via Cross-...
Mar 26, 2025HCL SX has a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unauthorized actions o...
Mar 3, 2025HCL iAutomate has a session fixation vulnerability where an attacker can hijack a user's authenticated session by fixing their session ID. This allows...
Feb 5, 2025HCL MyXalytics has a session fixation vulnerability where attackers can set a victim's session token via crafted URLs. This allows unauthorized access...
Jan 11, 2025HCL MyXalytics has an improper password policy vulnerability that allows attackers to guess or brute-force passwords when usernames are known. This af...
Jan 11, 2025HCL MyXalytics has an out-of-band resource load vulnerability where attackers can host malicious web content and trick the application into fetching a...
Jan 11, 2025This vulnerability in HCL MyXalytics allows attackers to access unauthorized data due to missing access control checks. It affects users of HCL MyXaly...
Jan 11, 2025HCL Traveler for Microsoft Outlook (HTMO) contains a control flow vulnerability where the application fails to properly manage execution flow, potenti...
Nov 12, 2024HCL BigFix Compliance generates error messages that may leak sensitive information about the system environment, users, or associated data. This vulne...
Nov 7, 2024This CVE describes a false positive detection issue where HCL Traveler for Microsoft Outlook (HTMO.exe) is incorrectly flagged as malicious software b...
Sep 26, 2024HCL Nomad server on Domino has an open proxy vulnerability allowing unauthenticated attackers to mask their source IP address. This enables attackers ...
Sep 25, 2024HCL Nomad server on Domino fails to properly handle users with limited Domino access, potentially allowing denial of service attacks. This affects org...
Jul 5, 2024The Domino Catalog template has a stored XSS vulnerability that allows attackers with document editing permissions to inject malicious scripts. When u...
Jun 6, 2024This CVE describes a Cross-Site Request Forgery vulnerability affecting session tokens in HCL software. If exploited, attackers could trick authentica...
May 18, 2024HCL DRYiCE MyXalytics has an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access other users' information ...
Jan 3, 2024CVE-2023-45722 is a path traversal vulnerability in HCL DRYiCE MyXalytics that allows attackers to read arbitrary files on the system by manipulating ...
Jan 3, 2024HCL DRYiCE MyXalytics has an unauthenticated file upload vulnerability that allows attackers to upload malicious files without authentication. This af...
Jan 3, 2024HCL DRYiCE MyXalytics uses a broken cryptographic algorithm for encryption, potentially allowing attackers to decrypt sensitive information. This affe...
Jan 3, 2024An unauthenticated stored cross-site scripting (XSS) vulnerability in BigFix Server version 9.5.12.68 allows attackers to inject malicious scripts int...
Dec 21, 2023CVE-2023-37519 is an unauthenticated stored cross-site scripting (XSS) vulnerability in the Download Status Report feature of BigFix Server. Attackers...
Dec 21, 2023HCL Compass has weak password requirements that allow attackers to easily guess passwords and compromise user accounts. This affects all HCL Compass i...
Oct 19, 2023HCL Compass fails to properly invalidate user sessions upon logout, allowing session hijacking. Attackers who obtain valid session identifiers can reu...
Oct 19, 2023HCL Compass has an unrestricted file upload vulnerability that allows attackers to upload malicious files containing executable code. This could lead ...
Oct 18, 2023This vulnerability allows a local attacker to gain elevated privileges on Windows systems running HCL AppScan Presence service. Attackers can exploit ...
Oct 17, 2023A persistent cross-site scripting (XSS) vulnerability in Unica Campaign allows attackers to inject malicious scripts into a specific field. When users...
Aug 3, 2023This vulnerability allows authenticated attackers with specific permissions to perform XML External Entity (XXE) attacks against Unica applications by...
Aug 3, 2023This CVE describes a persistent cross-site scripting (XSS) vulnerability in a specific field of the Unica Platform. An attacker can inject malicious s...
Aug 3, 2023HCL Verse contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When victims vi...
Aug 1, 2023This vulnerability affects OSD Bare Metal Servers using weak cryptographic algorithms, potentially allowing attackers to decrypt sensitive data or byp...
Jun 22, 2023HCL Workload Automation versions 9.4, 9.5, and 10.1 contain an XML External Entity (XXE) vulnerability that allows remote attackers to read sensitive ...
Apr 26, 2023HCL Compass has a Cross-Origin Resource Sharing (CORS) vulnerability that allows attackers to trick authenticated users into making unauthorized reque...
Apr 2, 2023This vulnerability allows attackers to redirect users to malicious websites by exploiting the Feedback action on the manager page. It affects HCL soft...
Feb 12, 2023CVE-2021-27779 is a critical information disclosure vulnerability in HCL VersionVault Express that exposes sensitive information. Attackers can exploi...
May 25, 2022CVE-2021-27777 is an XML External Entity (XXE) injection vulnerability in HCL Domino that allows attackers to read arbitrary files from the server fil...
May 12, 2022CVE-2021-27771 is a path traversal vulnerability in HCL Sametime chat application where attackers can modify user session IDs to upload arbitrary file...
May 12, 2022CVE-2021-27764 is a security misconfiguration vulnerability in HCL Domino WebUI where cookies are set without HTTPOnly flags. This allows attackers to...
May 6, 2022This vulnerability in BigFix Compliance allows attackers to decrypt TLS-encrypted network traffic when TLS-RSA cipher suites are enabled without TLS 2...
Mar 4, 2022CVE-2020-14255 is a vulnerability in HCL Digital Experience 9.5 containers that allows unauthorized access to sensitive data through crafted requests....
Feb 2, 2021CVE-2020-14224 is a critical stack buffer overflow vulnerability in HCL Notes v9 client's MIME message handling. An unauthenticated remote attacker co...
Dec 18, 2020A stack buffer overflow vulnerability in HCL Notes client MIME message handling allows unauthenticated remote attackers to crash the client or execute...
Dec 14, 2020CVE-2020-14260 is a critical buffer overflow vulnerability in HCL Domino's DXL component that allows remote code execution. Attackers can exploit impr...
Dec 2, 2020Why Monitor Hcltech Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 100+ known vulnerabilities affecting Hcltech products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Hcltech packages in under 60 seconds. No agents required - completely agentless scanning that works across Hcltech deployments.
Free vulnerability database: Access detailed information about every Hcltech CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Hcltech CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions