Vulnerabilidades em HCLSoftware

94 resultados
Análise Vexday

HCLSoftware apresenta volume significativo de vulnerabilidades (74 CVEs), com 55 divulgadas nos últimos 90 dias, indicando atividade recente relevante. A ausência de exploração ativa conhecida (0 KEV) e de vulnerabilidades críticas reduz a urgência imediata, mas a fraqueza dominante em exposição de informações (CWE-200) requer atenção em ambientes sensíveis.

CVE-2025-15619LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2026-21768MEDIUMHCL Verse for Android is susceptible to an injection vulnerabilityEPSS 0.2%CVE-2026-56582LOWHCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.EPSS 0.2%CVE-2026-56581LOWHCL MyCloud was affected with Cookie Attribute Path Not SetEPSS 0.2%CVE-2025-68833MEDIUMHCL Hive is affected by use of a cryptographic primitive with a risky implementationEPSS 0.2%CVE-2026-21825MEDIUMHCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search centerEPSS 0.2%CVE-2025-59868MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposureEPSS 0.2%CVE-2026-21827LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.2%CVE-2026-21790MEDIUMHCL Traveler is susceptible to a weak default HTTP header validation vulnerabilityEPSS 0.1%CVE-2026-21785MEDIUMHCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security PolicyEPSS 0.1%CVE-2026-56459MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosureEPSS 0.1%CVE-2026-21761MEDIUMCORS Misconfiguration in DevOps LoopEPSS 0.1%CVE-2026-56585LOWHCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingEPSS 0.1%CVE-2026-21826MEDIUMHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionEPSS 0.1%CVE-2026-21764LOWInsufficient Input Validation in DevOps LoopEPSS 0.1%CVE-2026-56619MEDIUMHCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS)EPSS 0.1%CVE-2024-23572MEDIUMHCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this iEPSS 0.1%CVE-2023-37508LOWHCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-21789MEDIUMHCL Connections is vulnerable to broken access controlEPSS 0.1%CVE-2026-56586LOWHCL IEM was affected with X-Content-Type-Options Header MissingEPSS 0.1%