hcltech

395 tracked vulnerabilities.

CVE-2024-30151 HIGH
HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability
May 06, 2026
CVSS 8.3
EPSS 0.00
CVE-2024-42210 HIGH
HCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS) vulnerability
Mar 19, 2026
CVSS 7.6
EPSS 0.00
CVE-2024-42192 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.14 - Credential Leakage
Oct 16, 2025
CVSS 5.5
EPSS 0.00
CVE-2024-42209 LOW
HCL Connections - Exposure of Sensitive Information via Improper Request Handling
Jul 17, 2025
CVSS 3.5
EPSS 0.00
CVE-2024-42191 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.12 - COM Hijacking via Uncontrolled Search Path Element
May 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-42190 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.12 - DLL Hijacking
May 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-42213 MEDIUM
HCL BigFix Compliance - Information Disclosure via Temporary Files
May 05, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-42212 MEDIUM
HCL BigFix Compliance - Sensitive Cookie with Improper SameSite Attribute
May 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-30146 MEDIUM
HCL Domino Leap 1.1.3-1.1.4 - Improper Access Control in Application Import Endpoint
Apr 30, 2025
CVSS 4.1
EPSS 0.00
CVE-2024-30145 MEDIUM
Hcltech HCL Domino Volt and Domino Leap 1.1 through 1.1.5 - Client-Side Script Injection
Apr 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-30115 MEDIUM
HCL Domino Leap 1.1-1.1.3 - Stored Cross-Site Scripting via HTML Widget
Apr 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2024-30152 MEDIUM
HCL SX v21 - Use of a Broken or Risky Cryptographic Algorithm
Apr 25, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-30127 LOW
HCL Leap < 9.3.9 - Sensitive Data Exposure via Missing Cache Headers
Apr 24, 2025
CVSS 3.2
EPSS 0.00
CVE-2024-30147 MEDIUM
HCL Leap - Client-Side Code Injection
Apr 24, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-30114 LOW
HCL Leap < 9.3.6 - Stored Cross-Site Scripting in Authoring Environment
Apr 24, 2025
CVSS 3.7
EPSS 0.00
CVE-2024-30113 MEDIUM
HCL Leap < 9.3.6 - Stored Cross-Site Scripting via HTML Widget
Apr 24, 2025
CVSS 6.3
EPSS 0.00
CVE-2024-30148 MEDIUM
HCL Leap < 9.3.8 - Improper Access Control via Application Import Endpoint
Apr 24, 2025
CVSS 4.1
EPSS 0.00
CVE-2024-42178 LOW
HCL MyXalytics - Unauthenticated Information Disclosure via Unrestricted URL Access
Apr 17, 2025
CVSS 2.5
EPSS 0.00
CVE-2024-42177 LOW
HCL MyXalytics - Inadequate Encryption Strength via SSL/TLS Protocol
Apr 17, 2025
CVSS 2.6
EPSS 0.00
CVE-2024-42193 HIGH
HCL BigFix Platform 10.0.0-10.0.12 - Improper Certificate Validation
Apr 15, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-42200 MEDIUM
HCL BigFix Platform 10.0.0-10.0.12 - Stored Cross-Site Scripting in Web Reports
Apr 15, 2025
CVSS 5.4
EPSS 0.00
CVE-2024-42189 MEDIUM
HCL BigFix Platform 10.0.0-10.0.12 - Denial of Service via API Parameter
Apr 15, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-42208 LOW
HCL Connections - Exposure of Sensitive Information via Improper Request Handling
Apr 04, 2025
CVSS 3.5
EPSS 0.00
CVE-2024-30155 MEDIUM
HCL SX - Sensitive Cookie with Improper SameSite Attribute
Mar 26, 2025
CVSS 5.5
EPSS 0.00
CVE-2024-42176 LOW
HCL MyXalytics - Concurrent Login Vulnerability
Mar 19, 2025
CVSS 2.6
EPSS 0.00