Vulnerabilidades em HCLSoftware
94 resultadosAnálise Vexday
HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.
CVE-2026-21837HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIEPSS 0.9%CVE-2026-21824HIGHA privilege escalation vulnerability affects HCL CommerceEPSS 0.4%CVE-2024-23565MEDIUMHCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password fEPSS 0.4%CVE-2024-23568MEDIUMHCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. DisplaEPSS 0.4%CVE-2026-56460MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityEPSS 0.4%CVE-2025-31964LOWHCL BigFix IVR is impacted by an improper service binding configurationEPSS 0.4%CVE-2024-23574MEDIUMHCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confEPSS 0.3%CVE-2024-23575MEDIUMHCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processingEPSS 0.3%CVE-2024-42214MEDIUMHCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of tEPSS 0.3%CVE-2026-21756HIGHHCL Hive is affected by a broken access control vulnerabilityEPSS 0.3%CVE-2023-37525MEDIUMHCL BigFix Compliance is vulnerable to a sensitive information disclosureEPSS 0.3%CVE-2024-23567MEDIUMHCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL paraEPSS 0.3%CVE-2026-56457MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationEPSS 0.3%CVE-2024-23577MEDIUMHCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requesteEPSS 0.3%CVE-2024-23571MEDIUMHCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to whichEPSS 0.3%CVE-2024-23569MEDIUMHCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" headerEPSS 0.3%CVE-2024-23570MEDIUMHCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulneraEPSS 0.3%CVE-2026-21783MEDIUMHCL Traveler is affected by sensitive information disclosureEPSS 0.3%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.3%CVE-2023-37524HIGHHCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of serviceEPSS 0.3%