Vulnerabilidades em HCLSoftware

94 resultados
Análise Vexday

HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.

CVE-2026-56620MEDIUMHCL BigFix Mobile is vulnerable to information disclosureEPSS 0.2%CVE-2026-21755MEDIUMHCL Hive is affected by a missing rate limitEPSS 0.2%CVE-2026-21821HIGHHCL BigFix SCM Reporting is affected by vulnerabilities in jQueryEPSS 0.2%CVE-2026-21760MEDIUMUnauthorized Access to Admin Functionality via Forced BrowsingEPSS 0.2%CVE-2024-23578MEDIUMHCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this requEPSS 0.2%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2025-31962LOWHCL BigFix IVR is impacted by an insufficient session expiration vulnerabilityEPSS 0.2%CVE-2026-21766MEDIUMHCL Digital Experience and Digital Experience Compose insufficiently protects credentialsEPSS 0.2%CVE-2025-15634MEDIUMHCL BigFix WebUI is affected by a missing authorization vulnerabilityEPSS 0.2%CVE-2025-31958LOWHCL BigFix Service Management (SM) is susceptible to HTTP Request SmugglingEPSS 0.2%CVE-2026-21762LOWMissing HTTP Security Headers in DevOps LoopEPSS 0.2%CVE-2026-56584LOWHCL IEM was affected with the Information disclosure nginx serverEPSS 0.2%CVE-2024-42210HIGHHCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-56577LOWHCL MyCloud affected by Weak Password PolicyEPSS 0.2%CVE-2026-21788MEDIUMHCL Connections is vulnerable to cross-site scripting (XSS)EPSS 0.2%CVE-2026-56547LOWAn input reflection vulnerability affects HCL TravelerEPSS 0.2%CVE-2026-21751HIGHHCL Hive is affected by use of a cryptographic primitive with a risky implementationEPSS 0.2%CVE-2025-62326MEDIUMHCL Digital Experience is susceptible to stored cross-site scripting (XSS)EPSS 0.2%CVE-2026-56538LOWHCL Connections is vulnerable to information disclosureEPSS 0.2%CVE-2026-56537LOWHCL Connections is vulnerable to information disclosureEPSS 0.2%