hcltech records
465 published records for vendor hcltech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')66
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor39
- CWE-209 Generation of Error Message Containing Sensitive Information19
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm15
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-284 Improper Access Control11
The weakness classes this vendor ships most often: where to look.
CWEAll records
465 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-14244No exploit | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated ahcltech · domino · CWE-787 | Critical9.8 | — | 3.0% | Dec 14, 2020 |
40Plan | CVE-2020-14224No exploit | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulthcltech · notes · CWE-787 | Critical9.8 | — | 2.3% | Dec 18, 2020 |
40Plan | CVE-2020-14268No exploit | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated athcltech · notes · CWE-787 | Critical9.8 | — | 2.3% | Dec 14, 2020 |
39Monitor | CVE-2020-14260No exploit | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input.hcltech · domino · CWE-120 | Critical9.8 | — | 1.5% | Dec 1, 2020 |
39Monitor | CVE-2019-4392No exploit | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized accesshcltech · appscan · CWE-798 | Critical9.8 | — | 1.4% | Feb 14, 2020 |
39Monitor | CVE-2020-4101No exploit | "HCL Digital Experience is susceptible to Server Side Request Forgery."hcltech · hcl digital experience · CWE-918 | Critical9.8 | — | 1.1% | Jun 11, 2020 |
39Monitor | CVE-2019-4393No exploit | HCL AppScan Standard is vulnerable to excessive authorization attemptshcltech · appscan · CWE-307 | Critical9.8 | — | 1.0% | Apr 7, 2020 |
39Monitor | CVE-2023-45723No exploit | Path Traversal which allows file upload capability affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-22 | Critical9.8 | — | 1.0% | Jan 2, 2024 |
39Monitor | CVE-2025-55270No exploit | HCL Aftermarket DPC is affected by Improper Input Validationhcltech · aftermarket cloud · CWE-20 | Critical9.8 | — | 1.0% | Mar 26, 2026 |
39Monitor | CVE-2021-27762No exploit | HCL BigFix Platform is affected by misconfigured security-related HTTP headershcltech · bigfix platform | Critical9.8 | — | 0.7% | May 6, 2022 |
39Monitor | CVE-2025-52626No exploit | HCL AION is susceptible to Potential Command Injection vulnerabilityhcltech · aion · CWE-78 | Critical9.8 | — | 0.7% | Feb 3, 2026 |
39Monitor | CVE-2023-45722No exploit | Path Traversal Arbitrary File Read affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-22 | Critical9.8 | — | 0.7% | Jan 2, 2024 |
39Monitor | CVE-2021-27786No exploit | HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trustedhcltech · onetest server · CWE-942 | Critical9.8 | — | 0.6% | Jun 9, 2022 |
39Monitor | CVE-2023-50347No exploit | Insecure SQL Interface affects HCL DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-89 | Critical9.8 | — | 0.6% | Apr 9, 2024 |
39Monitor | CVE-2023-45724No exploit | Unauthenticated File Upload affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-434 | Critical9.8 | — | 0.5% | Jan 2, 2024 |
39Monitor | CVE-2024-30110No exploit | Lack of input validation vulnerability affects DRYiCE AEX v10hcltech · dryice aex · CWE-20 | Critical9.8 | — | 0.5% | Jun 28, 2024 |
39Monitor | CVE-2023-37503No exploit | A weak password requirements vulnerability affects HCL Compasshcltech · hcl compass · CWE-521 | Critical9.8 | — | 0.5% | Oct 18, 2023 |
39Monitor | CVE-2025-59872No exploit | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,hcltech · zie for web · CWE-209 | Critical9.8 | — | 0.5% | Jun 17, 2026 |
39Monitor | CVE-2024-42172No exploit | HCL MyXalytics is affected by broken authenticationhcltech · dryice myxalytics · CWE-287 | Critical9.8 | — | 0.4% | Jan 11, 2025 |
39Monitor | CVE-2025-31998No exploit | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive informationhcltech · unica centralized offer management · CWE-209 | Critical9.8 | — | 0.4% | Oct 12, 2025 |
39Monitor | CVE-2026-56453No exploit | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.hcltech · dfxanalytics · CWE-294 | Critical9.8 | — | 0.4% | Jul 16, 2026 |
39Monitor | CVE-2025-52618No exploit | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerabilityhcltech · bigfix saas · CWE-89 | Critical9.8 | — | 0.3% | Aug 15, 2025 |
39Monitor | CVE-2025-52660No exploit | HCL AION is affected by an Host Header Injection vulnerabilityhcltech · aion · CWE-644 | Critical9.8 | — | 0.3% | Jan 19, 2026 |
39Monitor | CVE-2025-55261No exploit | HCL Aftermarket DPC is affected by Missing Functional Level Access Controlhcltech · aftermarket cloud · CWE-284 | Critical9.8 | — | 0.3% | Mar 26, 2026 |
39Monitor | CVE-2025-55267No exploit | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerabilityhcltech · aftermarket cloud · CWE-434 | Critical9.8 | — | 0.3% | Mar 26, 2026 |
- CVE-2020-1424440Plan
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated a
CriticalCVSS 9.8No exploitEPSS 3%hcltech · dominoDec 14, 2020
- CVE-2020-1422440Plan
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker result
CriticalCVSS 9.8No exploitEPSS 2%hcltech · notesDec 18, 2020
- CVE-2020-1426840Plan
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated at
CriticalCVSS 9.8No exploitEPSS 2%hcltech · notesDec 14, 2020
- CVE-2020-1426039Monitor
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input.
CriticalCVSS 9.8No exploitEPSS 1%hcltech · dominoDec 1, 2020
- CVE-2019-439239Monitor
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access
CriticalCVSS 9.8No exploitEPSS 1%hcltech · appscanFeb 14, 2020
- CVE-2020-410139Monitor
"HCL Digital Experience is susceptible to Server Side Request Forgery."
CriticalCVSS 9.8No exploitEPSS 1%hcltech · hcl digital experienceJun 11, 2020
- CVE-2019-439339Monitor
HCL AppScan Standard is vulnerable to excessive authorization attempts
CriticalCVSS 9.8No exploitEPSS 1%hcltech · appscanApr 7, 2020
- CVE-2023-4572339Monitor
Path Traversal which allows file upload capability affects DRYiCE MyXalytics
CriticalCVSS 9.8No exploitEPSS 1%hcltech · dryice myxalyticsJan 2, 2024
- CVE-2025-5527039Monitor
HCL Aftermarket DPC is affected by Improper Input Validation
CriticalCVSS 9.8No exploitEPSS 1%hcltech · aftermarket cloudMar 26, 2026
- CVE-2021-2776239Monitor
HCL BigFix Platform is affected by misconfigured security-related HTTP headers
CriticalCVSS 9.8No exploitEPSS 1%hcltech · bigfix platformMay 6, 2022
- CVE-2025-5262639Monitor
HCL AION is susceptible to Potential Command Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%hcltech · aionFeb 3, 2026
- CVE-2023-4572239Monitor
Path Traversal Arbitrary File Read affects DRYiCE MyXalytics
CriticalCVSS 9.8No exploitEPSS 1%hcltech · dryice myxalyticsJan 2, 2024
- CVE-2021-2778639Monitor
HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted
CriticalCVSS 9.8No exploitEPSS 1%hcltech · onetest serverJun 9, 2022
- CVE-2023-5034739Monitor
Insecure SQL Interface affects HCL DRYiCE MyXalytics
CriticalCVSS 9.8No exploitEPSS 1%hcltech · dryice myxalyticsApr 9, 2024
- CVE-2023-4572439Monitor
Unauthenticated File Upload affects DRYiCE MyXalytics
CriticalCVSS 9.8No exploitEPSS 1%hcltech · dryice myxalyticsJan 2, 2024
- CVE-2024-3011039Monitor
Lack of input validation vulnerability affects DRYiCE AEX v10
CriticalCVSS 9.8No exploitEPSS 0%hcltech · dryice aexJun 28, 2024
- CVE-2023-3750339Monitor
A weak password requirements vulnerability affects HCL Compass
CriticalCVSS 9.8No exploitEPSS 0%hcltech · hcl compassOct 18, 2023
- CVE-2025-5987239Monitor
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
CriticalCVSS 9.8No exploitEPSS 0%hcltech · zie for webJun 17, 2026
- CVE-2024-4217239Monitor
HCL MyXalytics is affected by broken authentication
CriticalCVSS 9.8No exploitEPSS 0%hcltech · dryice myxalyticsJan 11, 2025
- CVE-2025-3199839Monitor
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information
CriticalCVSS 9.8No exploitEPSS 0%hcltech · unica centralized offer managementOct 12, 2025
- CVE-2026-5645339Monitor
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.
CriticalCVSS 9.8No exploitEPSS 0%hcltech · dfxanalyticsJul 16, 2026
- CVE-2025-5261839Monitor
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%hcltech · bigfix saasAug 15, 2025
- CVE-2025-5266039Monitor
HCL AION is affected by an Host Header Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%hcltech · aionJan 19, 2026
- CVE-2025-5526139Monitor
HCL Aftermarket DPC is affected by Missing Functional Level Access Control
CriticalCVSS 9.8No exploitEPSS 0%hcltech · aftermarket cloudMar 26, 2026
- CVE-2025-5526739Monitor
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability
CriticalCVSS 9.8No exploitEPSS 0%hcltech · aftermarket cloudMar 26, 2026