Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Hcltech

185 known vulnerabilities

1
CRITICAL
13
HIGH
49
MEDIUM
72
LOW

Top Products

aion 22 aftermarket cloud 17 bigfix service management 16 dfxanalytics 14 icontrol 13 dryice mycloud 7 devops plan 5 connections 4 intelliops event management 4 devops loop 4
135 CVEs · Page 1/3
4.8
CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using

3.7
CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce

3.7
CVE-2026-56571

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions

3.7
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va

4.0
CVE-2026-56569

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config

3.7
CVE-2026-56568

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv

5.1
CVE-2026-56567

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern

3.5
CVE-2026-56538

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi

3.5
CVE-2026-56537

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar

3.1
CVE-2026-56583

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h

3.1
CVE-2026-56582

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen

2.6
CVE-2026-56581

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session

2.2
CVE-2026-56580

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit

3.1
CVE-2026-56579

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor

2.2
CVE-2026-56578

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities

3.1
CVE-2026-56577

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o

3.1
CVE-2026-56586

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man

3.1
CVE-2026-56585

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli

3.7
CVE-2026-56587

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma

3.7
CVE-2026-56584

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software

7.5
CVE-2023-37507

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon

6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v

3.1
CVE-2026-21764

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric

3.7
CVE-2026-21762

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag

4.2
CVE-2026-21761

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may

4.6
CVE-2026-21760

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a

5.3
CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently

5.3
CVE-2026-56455

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat

5.9
CVE-2026-56454

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy

5.5
CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter

3.1
CVE-2026-35145

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to

3.0
CVE-2026-35143

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"

2.6
CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad

2.6
CVE-2026-35141

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce

3.0
CVE-2026-35140

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat

8.2
CVE-2026-35149

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us

6.3
CVE-2026-35148

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar

8.2
CVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif

6.3
CVE-2026-35146

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn

5.5
CVE-2025-59868

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an

7.7
CVE-2023-37524

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi

6.7
CVE-2024-23581

The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized

3.1
CVE-2025-62340

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where

4.3
CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t

6.5
CVE-2026-4096

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th

8.8
CVE-2026-21837

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An att

6.1
CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker ca

6.1
CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.

7.1
CVE-2025-52612

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script

3.1
CVE-2025-52611

HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to

Frequently Asked Questions

How many CVEs affect Hcltech?

Hcltech has 185 CVE records in our database, including 2 critical and 14 high severity vulnerabilities.

What are the most severe Hcltech vulnerabilities?

Hcltech has 2 critical severity (CVSS 9.0+) and 14 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Hcltech vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Hcltech products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Hcltech Vulnerabilities

CyberStrike scans your infrastructure for Hcltech vulnerabilities and provides real-time remediation guidance.

Get Started