Filtered by vendor Hcltech
Subscribe
Total
442 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-62326 | 1 Hcltech | 1 Digital Experience | 2026-06-17 | N/A | 6.1 MEDIUM |
| HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. | |||||
| CVE-2025-62320 | 1 Hcltech | 9 Unica, Unica Audience Central, Unica Campaign and 6 more | 2026-06-17 | N/A | 4.7 MEDIUM |
| HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser. | |||||
| CVE-2025-62319 | 1 Hcltech | 2 Unica, Unica Audience Central | 2026-06-17 | N/A | 9.8 CRITICAL |
| Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application. | |||||
| CVE-2025-59870 | 1 Hcltech | 1 Myxalytics | 2026-06-17 | N/A | 7.4 HIGH |
| HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | |||||
| CVE-2025-59854 | 1 Hcltech | 1 Dfxanalytics | 2026-06-17 | N/A | 3.1 LOW |
| HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security Policy (CSP). | |||||
| CVE-2025-59853 | 1 Hcltech | 1 Dfxanalytics | 2026-06-17 | N/A | 3.1 LOW |
| HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations. | |||||
| CVE-2025-59852 | 1 Hcltech | 1 Dfxanalytics | 2026-06-17 | N/A | 3.7 LOW |
| HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information. | |||||
| CVE-2025-59851 | 1 Hcltech | 1 Dfxanalytics | 2026-06-17 | N/A | 3.7 LOW |
| HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to gain unauthorized access or compromise the application. | |||||
| CVE-2025-55277 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 2.6 LOW |
| HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application. | |||||
| CVE-2025-55276 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 3.1 LOW |
| HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout. | |||||
| CVE-2025-55275 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 3.7 LOW |
| HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user. | |||||
| CVE-2025-55274 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 2.6 LOW |
| HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user. | |||||
| CVE-2025-55273 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 4.3 MEDIUM |
| HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | |||||
| CVE-2025-55272 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 3.1 LOW |
| HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks. | |||||
| CVE-2025-55271 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 3.1 LOW |
| HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response.. | |||||
| CVE-2025-55270 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 3.5 LOW |
| HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc. | |||||
| CVE-2025-55269 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 4.2 MEDIUM |
| HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. | |||||
| CVE-2025-55268 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 4.3 MEDIUM |
| HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | |||||
| CVE-2025-55267 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 5.7 MEDIUM |
| HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | |||||
| CVE-2025-55266 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 5.9 MEDIUM |
| HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user. | |||||
