Vulnerabilities
505 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56609 +1 in the same advisory: …56608 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2026-56568 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2026-56538 +1 in the same advisory: …56537 | An endpoint in HCL Connections is vulnerable to information disclosure. An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. NVD description · AI analysis pending | 3.5 | <1% |
| — | ||
| CVE-2026-56577 | HCL MyCloud was affected with Weak Password Policy. HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2026-56584 | HCL IEM was affected with the Information disclosure nginx server. HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2023-37507 +1 in the same advisory: …37508 | HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-21761 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2026-56453 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-35147 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. NVD description · AI analysis pending | 8.2 group max | <1% |
| — | ||
| CVE-2026-56458 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-56457 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2023-37524 +1 in the same advisory: …59868 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2024-23581 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-62340 | HCL iControl was affected by Inadequate Session Timeout vulnerability. HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2025-59872 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-4096 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2026-21837 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. NVD description · AI analysis pending | 8.7 | <1% |
| — |