hcltech

395 tracked vulnerabilities.

CVE-2025-31970 MEDIUM
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
May 06, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-31981 MEDIUM
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption
Apr 21, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-31958 LOW
HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling
Apr 21, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-52641 LOW
Internal Filesystem Exploration vulnerability
Apr 15, 2026
CVSS 2.9
EPSS 0.00
CVE-2025-55264 MEDIUM
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change
Mar 26, 2026
CVSS 5.5
EPSS 0.00
CVE-2025-55263 HIGH
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data
Mar 26, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-55262 HIGH
HCL Aftermarket DPC is affected by SQL Injection
Mar 26, 2026
CVSS 8.3
EPSS 0.00
CVE-2025-55261 HIGH
HCL Aftermarket DPC is affected by Missing Functional Level Access Control
Mar 26, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-55277 LOW
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability
Mar 26, 2026
CVSS 2.6
EPSS 0.00
CVE-2025-55276 LOW
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability
Mar 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-55275 LOW
HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability
Mar 26, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-55274 LOW
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability
Mar 26, 2026
CVSS 2.6
EPSS 0.00
CVE-2025-55273 MEDIUM
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability
Mar 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-55272 LOW
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability
Mar 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-55271 LOW
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
Mar 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-55270 LOW
HCL Aftermarket DPC is affected by Improper Input Validation
Mar 26, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-55269 MEDIUM
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability
Mar 26, 2026
CVSS 4.2
EPSS 0.00
CVE-2025-55268 MEDIUM
HCL Aftermarket DPC is affected by Spamming Vulnerability
Mar 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-55267 MEDIUM
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability
Mar 26, 2026
CVSS 5.7
EPSS 0.00
CVE-2025-55266 MEDIUM
HCL Aftermarket DPC is affected by Session Fixation
Mar 26, 2026
CVSS 5.9
EPSS 0.00
CVE-2025-55265 MEDIUM
HCL Aftermarket DPC is affected by File Discovery
Mar 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-62320 MEDIUM
HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform
Mar 17, 2026
CVSS 4.7
EPSS 0.00
CVE-2025-31966 LOW
Boolean-Based SQL Injection in Multiple Unica Components
Mar 17, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-52649 LOW
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature
Mar 16, 2026
CVSS 1.8
EPSS 0.00
CVE-2025-52646 LOW
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries.
Mar 16, 2026
CVSS 2.2
EPSS 0.00