Vulnerabilidades em HCLSoftware
77 resultadosAnálise Vexday
HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.
CVE-2026-21837HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIEPSS 0.9%CVE-2025-31964LOWHCL BigFix IVR is impacted by an improper service binding configurationEPSS 0.3%CVE-2023-37525MEDIUMHCL BigFix Compliance is vulnerable to a sensitive information disclosureEPSS 0.3%CVE-2026-21783MEDIUMHCL Traveler is affected by sensitive information disclosureEPSS 0.3%CVE-2026-21836MEDIUMHCL DominoIQ is affected by broken access controlEPSS 0.3%CVE-2025-52603LOWHCL Connections is vulnerable to information disclosureEPSS 0.3%CVE-2025-31990MEDIUMHCL DevOps Velocity is susceptible to a Denial of Service vulnerabilityEPSS 0.3%CVE-2023-37507MEDIUMAn information disclosure vulnerability affects HCL DevOps PlanEPSS 0.2%CVE-2025-62328LOWHCL Nomad server on Domino is affected by a missing default frame-ancestors directiveEPSS 0.2%CVE-2024-23568MEDIUMHCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. DisplaEPSS 0.2%CVE-2024-23565MEDIUMHCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password fEPSS 0.2%CVE-2026-21824HIGHA privilege escalation vulnerability affects HCL CommerceEPSS 0.2%CVE-2025-62327MEDIUMHCL DevOps Deploy is susceptible to insufficiently protected credentialsEPSS 0.2%CVE-2025-31991MEDIUMHCL DevOps Velocity is susceptible to brute-force attacksEPSS 0.2%CVE-2025-15633MEDIUMHCL BigFix WebUI is affected by an improper authorization vulnerabilityEPSS 0.2%CVE-2026-56460MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2024-42214MEDIUMHCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of tEPSS 0.2%CVE-2024-23574MEDIUMHCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confEPSS 0.2%CVE-2024-23575MEDIUMHCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processingEPSS 0.2%