hcltech

395 tracked vulnerabilities.

CVE-2026-21767 MEDIUM
HCL BigFix Platform is affected by insufficient authentication
Apr 02, 2026
CVSS 4.0
EPSS 0.00
CVE-2026-21765 HIGH
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
Apr 02, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-21783 MEDIUM
HCL Traveler is affected by sensitive information disclosure
Mar 24, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-21788 MEDIUM
HCL Connections 8 - Cross-Site Scripting
Mar 19, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-21791 LOW
HCL Sametime for Android - Info Disclosure
Mar 10, 2026
CVSS 3.3
EPSS 0.00
CVE-2026-21786 LOW
HCL Sametime for iOS - Info Disclosure
Mar 05, 2026
CVSS 3.3
EPSS 0.00
CVE-2025-31985 LOW
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
May 20, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-31973 MEDIUM
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'
May 20, 2026
CVSS 4.0
EPSS 0.00
CVE-2025-15634 MEDIUM
HCL BigFix WebUI is affected by a missing authorization vulnerability
May 09, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-15633 MEDIUM
HCL BigFix WebUI is affected by an improper authorization vulnerability
May 09, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-31974 LOW
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only
May 06, 2026
CVSS 3.9
EPSS 0.00
CVE-2025-31960 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
May 06, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-52613 MEDIUM
HCL BigFix Service Management (SM) is affected by use of a vulnerable component
May 06, 2026
CVSS 4.6
EPSS 0.00
CVE-2025-31984 LOW
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header
May 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-31983 LOW
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
May 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-31982 LOW
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl
May 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-31978 MEDIUM
HCL BigFix Service Management (SM) does not adequately sanitize or safely render
May 06, 2026
CVSS 4.6
EPSS 0.00
CVE-2025-31976 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
May 06, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-31975 LOW
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.
May 06, 2026
CVSS 2.6
EPSS 0.00
CVE-2025-31959 LOW
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.
May 06, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-31957 LOW
HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.
May 06, 2026
CVSS 2.6
EPSS 0.00
CVE-2025-59854 LOW
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability
May 06, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-59853 LOW
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability
May 06, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-59852 LOW
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability
May 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-59851 LOW
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
May 06, 2026
CVSS 3.7
EPSS 0.00