Vulnerabilities in HCLSoftware
94 resultsVexday analysis
HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.
CVE-2026-56587LOWHCL IEM was affected with Strict transport security not enforcedEPSS 0.2%CVE-2025-62328LOWHCL Nomad server on Domino is affected by a missing default frame-ancestors directiveEPSS 0.2%CVE-2024-23573LOWHCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects theEPSS 0.2%CVE-2026-21840LOWHCL BigFix Platform is affected by a user enumeration vulnerabilityEPSS 0.2%CVE-2025-68825HIGHHCL Hive is affected by incorrect default permissionsEPSS 0.2%CVE-2025-31991MEDIUMHCL DevOps Velocity is susceptible to brute-force attacksEPSS 0.2%CVE-2026-56619MEDIUMHCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS)EPSS 0.2%CVE-2025-15633MEDIUMHCL BigFix WebUI is affected by an improper authorization vulnerabilityEPSS 0.2%CVE-2026-21759MEDIUMHCL Hive is affected by an information exposure vulnerabilityEPSS 0.2%CVE-2026-21764LOWInsufficient Input Validation in DevOps LoopEPSS 0.2%CVE-2026-56583LOWHCL MyCloud was affected with Concurrent Login Vulnerability.EPSS 0.2%CVE-2023-37508LOWHCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-21755MEDIUMHCL Hive is affected by a missing rate limitEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2026-21760MEDIUMUnauthorized Access to Admin Functionality via Forced BrowsingEPSS 0.2%CVE-2026-21761MEDIUMCORS Misconfiguration in DevOps LoopEPSS 0.2%CVE-2026-56586LOWHCL IEM was affected with X-Content-Type-Options Header MissingEPSS 0.2%CVE-2024-23578MEDIUMHCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this requEPSS 0.2%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2025-31962LOWHCL BigFix IVR is impacted by an insufficient session expiration vulnerabilityEPSS 0.2%