Vulnerabilities in HCLSoftware
94 resultsVexday analysis
HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.
CVE-2026-21762LOWMissing HTTP Security Headers in DevOps LoopEPSS 0.3%CVE-2026-56584LOWHCL IEM was affected with the Information disclosure nginx serverEPSS 0.3%CVE-2026-56577LOWHCL MyCloud affected by Weak Password PolicyEPSS 0.3%CVE-2026-56547LOWAn input reflection vulnerability affects HCL TravelerEPSS 0.3%CVE-2024-23570MEDIUMHCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulneraEPSS 0.3%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.3%CVE-2026-21783MEDIUMHCL Traveler is affected by sensitive information disclosureEPSS 0.3%CVE-2023-37524HIGHHCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of serviceEPSS 0.3%CVE-2026-56537LOWHCL Connections is vulnerable to information disclosureEPSS 0.3%CVE-2026-56538LOWHCL Connections is vulnerable to information disclosureEPSS 0.3%CVE-2024-23566MEDIUMHCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various securityEPSS 0.3%CVE-2025-52603LOWHCL Connections is vulnerable to information disclosureEPSS 0.3%CVE-2026-21752HIGHHCL Hive is affected by a use of vulnerable third-party componentsEPSS 0.3%CVE-2026-21836MEDIUMHCL DominoIQ is affected by broken access controlEPSS 0.3%CVE-2026-56458MEDIUMHCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted DomainsEPSS 0.3%CVE-2025-31990MEDIUMHCL DevOps Velocity is susceptible to a Denial of Service vulnerabilityEPSS 0.3%CVE-2025-62327MEDIUMHCL DevOps Deploy is susceptible to insufficiently protected credentialsEPSS 0.3%CVE-2026-56578LOWHCL MyCloud was affected by Server Version DisclosureEPSS 0.3%CVE-2026-56585LOWHCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingEPSS 0.2%CVE-2026-56579LOWHCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.EPSS 0.2%