Записи hcltech
460 опубликованных записей вендора hcltech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor35
- CWE-209 Generation of Error Message Containing Sensitive Information19
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm15
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-284 Improper Access Control11
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
460 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-14244Эксплойта нет | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated ahcltech · domino · CWE-787 | Критическая9,8 | — | 3,0 % | 14 дек. 2020 г. |
40В плане | CVE-2020-14224Эксплойта нет | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulthcltech · notes · CWE-787 | Критическая9,8 | — | 2,3 % | 18 дек. 2020 г. |
40В плане | CVE-2020-14268Эксплойта нет | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated athcltech · notes · CWE-787 | Критическая9,8 | — | 2,3 % | 14 дек. 2020 г. |
39Наблюдать | CVE-2020-14260Эксплойта нет | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input.hcltech · domino · CWE-120 | Критическая9,8 | — | 1,5 % | 1 дек. 2020 г. |
39Наблюдать | CVE-2019-4392Эксплойта нет | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized accesshcltech · appscan · CWE-798 | Критическая9,8 | — | 1,4 % | 14 февр. 2020 г. |
39Наблюдать | CVE-2020-4101Эксплойта нет | "HCL Digital Experience is susceptible to Server Side Request Forgery."hcltech · hcl digital experience · CWE-918 | Критическая9,8 | — | 1,1 % | 11 июн. 2020 г. |
39Наблюдать | CVE-2019-4393Эксплойта нет | HCL AppScan Standard is vulnerable to excessive authorization attemptshcltech · appscan · CWE-307 | Критическая9,8 | — | 1,0 % | 7 апр. 2020 г. |
39Наблюдать | CVE-2023-45723Эксплойта нет | Path Traversal which allows file upload capability affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-22 | Критическая9,8 | — | 1,0 % | 2 янв. 2024 г. |
39Наблюдать | CVE-2025-55270Эксплойта нет | HCL Aftermarket DPC is affected by Improper Input Validationhcltech · aftermarket cloud · CWE-20 | Критическая9,8 | — | 1,0 % | 26 мар. 2026 г. |
39Наблюдать | CVE-2021-27762Эксплойта нет | HCL BigFix Platform is affected by misconfigured security-related HTTP headershcltech · bigfix platform | Критическая9,8 | — | 0,7 % | 6 мая 2022 г. |
39Наблюдать | CVE-2023-45722Эксплойта нет | Path Traversal Arbitrary File Read affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-22 | Критическая9,8 | — | 0,7 % | 2 янв. 2024 г. |
39Наблюдать | CVE-2025-52626Эксплойта нет | HCL AION is susceptible to Potential Command Injection vulnerabilityhcltech · aion · CWE-78 | Критическая9,8 | — | 0,6 % | 3 февр. 2026 г. |
39Наблюдать | CVE-2021-27786Эксплойта нет | HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trustedhcltech · onetest server · CWE-942 | Критическая9,8 | — | 0,6 % | 9 июн. 2022 г. |
39Наблюдать | CVE-2023-50347Эксплойта нет | Insecure SQL Interface affects HCL DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-89 | Критическая9,8 | — | 0,6 % | 9 апр. 2024 г. |
39Наблюдать | CVE-2023-45724Эксплойта нет | Unauthenticated File Upload affects DRYiCE MyXalyticshcltech · dryice myxalytics · CWE-434 | Критическая9,8 | — | 0,5 % | 2 янв. 2024 г. |
39Наблюдать | CVE-2024-30110Эксплойта нет | Lack of input validation vulnerability affects DRYiCE AEX v10hcltech · dryice aex · CWE-20 | Критическая9,8 | — | 0,5 % | 28 июн. 2024 г. |
39Наблюдать | CVE-2023-37503Эксплойта нет | A weak password requirements vulnerability affects HCL Compasshcltech · hcl compass · CWE-521 | Критическая9,8 | — | 0,5 % | 18 окт. 2023 г. |
39Наблюдать | CVE-2025-59872Эксплойта нет | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,hcltech · zie for web · CWE-209 | Критическая9,8 | — | 0,5 % | 17 июн. 2026 г. |
39Наблюдать | CVE-2024-42172Эксплойта нет | HCL MyXalytics is affected by broken authenticationhcltech · dryice myxalytics · CWE-287 | Критическая9,8 | — | 0,4 % | 11 янв. 2025 г. |
39Наблюдать | CVE-2025-31998Эксплойта нет | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive informationhcltech · unica centralized offer management · CWE-209 | Критическая9,8 | — | 0,4 % | 11 окт. 2025 г. |
39Наблюдать | CVE-2026-56453Эксплойта нет | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.hcltech · dfxanalytics · CWE-294 | Критическая9,8 | — | 0,4 % | 16 июл. 2026 г. |
39Наблюдать | CVE-2025-52618Эксплойта нет | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerabilityhcltech · bigfix saas · CWE-89 | Критическая9,8 | — | 0,3 % | 15 авг. 2025 г. |
39Наблюдать | CVE-2025-52660Эксплойта нет | HCL AION is affected by an Host Header Injection vulnerabilityhcltech · aion · CWE-644 | Критическая9,8 | — | 0,3 % | 19 янв. 2026 г. |
39Наблюдать | CVE-2025-55261Эксплойта нет | HCL Aftermarket DPC is affected by Missing Functional Level Access Controlhcltech · aftermarket cloud · CWE-284 | Критическая9,8 | — | 0,3 % | 26 мар. 2026 г. |
39Наблюдать | CVE-2025-55267Эксплойта нет | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerabilityhcltech · aftermarket cloud · CWE-434 | Критическая9,8 | — | 0,3 % | 26 мар. 2026 г. |
- CVE-2020-1424440В плане
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated a
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hcltech · domino14 дек. 2020 г.
- CVE-2020-1422440В плане
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker result
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hcltech · notes18 дек. 2020 г.
- CVE-2020-1426840В плане
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated at
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hcltech · notes14 дек. 2020 г.
- CVE-2020-1426039Наблюдать
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · domino1 дек. 2020 г.
- CVE-2019-439239Наблюдать
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · appscan14 февр. 2020 г.
- CVE-2020-410139Наблюдать
"HCL Digital Experience is susceptible to Server Side Request Forgery."
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · hcl digital experience11 июн. 2020 г.
- CVE-2019-439339Наблюдать
HCL AppScan Standard is vulnerable to excessive authorization attempts
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · appscan7 апр. 2020 г.
- CVE-2023-4572339Наблюдать
Path Traversal which allows file upload capability affects DRYiCE MyXalytics
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · dryice myxalytics2 янв. 2024 г.
- CVE-2025-5527039Наблюдать
HCL Aftermarket DPC is affected by Improper Input Validation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · aftermarket cloud26 мар. 2026 г.
- CVE-2021-2776239Наблюдать
HCL BigFix Platform is affected by misconfigured security-related HTTP headers
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · bigfix platform6 мая 2022 г.
- CVE-2023-4572239Наблюдать
Path Traversal Arbitrary File Read affects DRYiCE MyXalytics
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · dryice myxalytics2 янв. 2024 г.
- CVE-2025-5262639Наблюдать
HCL AION is susceptible to Potential Command Injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · aion3 февр. 2026 г.
- CVE-2021-2778639Наблюдать
HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · onetest server9 июн. 2022 г.
- CVE-2023-5034739Наблюдать
Insecure SQL Interface affects HCL DRYiCE MyXalytics
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · dryice myxalytics9 апр. 2024 г.
- CVE-2023-4572439Наблюдать
Unauthenticated File Upload affects DRYiCE MyXalytics
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · dryice myxalytics2 янв. 2024 г.
- CVE-2024-3011039Наблюдать
Lack of input validation vulnerability affects DRYiCE AEX v10
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · dryice aex28 июн. 2024 г.
- CVE-2023-3750339Наблюдать
A weak password requirements vulnerability affects HCL Compass
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · hcl compass18 окт. 2023 г.
- CVE-2025-5987239Наблюдать
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · zie for web17 июн. 2026 г.
- CVE-2024-4217239Наблюдать
HCL MyXalytics is affected by broken authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · dryice myxalytics11 янв. 2025 г.
- CVE-2025-3199839Наблюдать
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · unica centralized offer management11 окт. 2025 г.
- CVE-2026-5645339Наблюдать
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · dfxanalytics16 июл. 2026 г.
- CVE-2025-5261839Наблюдать
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · bigfix saas15 авг. 2025 г.
- CVE-2025-5266039Наблюдать
HCL AION is affected by an Host Header Injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · aion19 янв. 2026 г.
- CVE-2025-5526139Наблюдать
HCL Aftermarket DPC is affected by Missing Functional Level Access Control
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · aftermarket cloud26 мар. 2026 г.
- CVE-2025-5526739Наблюдать
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · aftermarket cloud26 мар. 2026 г.