Filtered by vendor Hcltech
Subscribe
Total
442 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-56583 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse. | |||||
| CVE-2026-56580 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.2 LOW |
| HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system. | |||||
| CVE-2026-56577 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | |||||
| CVE-2026-56579 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security. | |||||
| CVE-2026-56581 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.6 LOW |
| HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens. | |||||
| CVE-2026-56578 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 2.2 LOW |
| HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions. | |||||
| CVE-2026-56582 | 1 Hcltech | 1 Dryice Mycloud | 2026-08-03 | N/A | 3.1 LOW |
| HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. | |||||
| CVE-2026-56584 | 1 Hcltech | 1 Intelliops Event Management | 2026-07-30 | N/A | 3.7 LOW |
| HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. | |||||
| CVE-2026-56587 | 1 Hcltech | 1 Intelliops Event Management | 2026-07-30 | N/A | 3.7 LOW |
| HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. | |||||
| CVE-2026-56585 | 1 Hcltech | 1 Intelliops Event Management | 2026-07-30 | N/A | 3.1 LOW |
| HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | |||||
| CVE-2026-56586 | 1 Hcltech | 1 Intelliops Event Management | 2026-07-30 | N/A | 3.1 LOW |
| HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | |||||
| CVE-2023-37507 | 1 Hcltech | 1 Devops Plan | 2026-07-29 | N/A | 7.5 HIGH |
| HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | |||||
| CVE-2023-37508 | 1 Hcltech | 1 Devops Plan | 2026-07-29 | N/A | 6.1 MEDIUM |
| HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present. | |||||
| CVE-2025-36364 | 1 Hcltech | 1 Devops Plan | 2026-07-27 | N/A | 6.2 MEDIUM |
| IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. | |||||
| CVE-2025-36363 | 1 Hcltech | 1 Devops Plan | 2026-07-27 | N/A | 5.9 MEDIUM |
| IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | |||||
| CVE-2026-4096 | 1 Hcltech | 1 Devops Plan | 2026-07-27 | N/A | 6.5 MEDIUM |
| IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking | |||||
| CVE-2024-22348 | 2 Hcltech, Ibm | 2 Devops Velocity, Urbancode Velocity | 2026-07-27 | N/A | 5.3 MEDIUM |
| IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. | |||||
| CVE-2024-22349 | 2 Hcltech, Ibm | 2 Devops Velocity, Urbancode Velocity | 2026-07-27 | N/A | 4.0 MEDIUM |
| IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system. | |||||
| CVE-2024-22347 | 2 Hcltech, Ibm | 2 Devops Velocity, Urbancode Velocity | 2026-07-27 | N/A | 5.9 MEDIUM |
| IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |||||
| CVE-2025-15634 | 1 Hcltech | 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more | 2026-07-25 | N/A | 4.3 MEDIUM |
| A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |||||
