Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 449 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42212 1 Hcltech 1 Bigfix Compliance 2026-06-17 N/A 5.4 MEDIUM
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
CVE-2024-42210 1 Hcltech 1 Unica 2026-06-17 N/A 7.6 HIGH
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
CVE-2024-42209 1 Hcltech 1 Connections 2026-06-17 N/A 3.5 LOW
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.
CVE-2024-42208 1 Hcltech 1 Connections 2026-06-17 N/A 3.5 LOW
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2024-42207 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 5.5 MEDIUM
HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.
CVE-2024-42200 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 5.4 MEDIUM
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
CVE-2024-42193 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 8.1 HIGH
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
CVE-2024-42192 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 5.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
CVE-2024-42191 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 6.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
CVE-2024-42190 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-17 N/A 6.5 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
CVE-2024-42189 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
CVE-2024-42188 1 Hcltech 1 Connections 2026-06-17 N/A 3.7 LOW
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
CVE-2024-42181 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 1.6 LOW
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVE-2024-42180 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 1.6 LOW
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
CVE-2024-42179 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.0 LOW
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.
CVE-2024-42178 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.5 LOW
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.
CVE-2024-42177 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.6 LOW
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system.
CVE-2024-42176 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.6 LOW
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.
CVE-2024-42175 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 2.6 LOW
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like SQL injection, XSS, and buffer overflow.
CVE-2024-42174 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 3.7 LOW
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.