CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “hcltech”

290 vulnerabilities found for “hcltech”

Page 1 of 15

CVE-2024-23576
HIGH7.1

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce
Network
Published May 14, 2024
Page 1 of 15
CVE-2022-38656
HIGH8.6

HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

hcltechsw / hcl_commerce
Network
Published Dec 12, 2022
CVE-2021-27785
LOW3.9

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

hcltechsw / hcl_commerce+1
Physical
Published Jul 30, 2022
CVE-2021-27771
HIGH8.2

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

hcltech / sametime
Network
Published May 12, 2022
CVE-2021-27769
MEDIUM5.3

Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.

hcltech / sametime
Network
Published May 12, 2022
CVE-2021-27770
MEDIUM6.8

The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.

hcltech / sametime
Network
Published May 12, 2022
CVE-2021-27772
HIGH7.1

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.

hcltech / sametime
Network
Published May 12, 2022
CVE-2021-27751
MEDIUM4.4

HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

hcltechsw / hcl_commerce+2
Local
Published May 6, 2022
CVE-2021-27757
HIGH7.5

" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."

hcltech / bigfix_insights
Network
Published Mar 4, 2022
CVE-2021-27741
CRITICAL9.1

" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

hcltechsw / hcl_commerce+2
Network
Published Aug 13, 2021
CVE-2020-14274
HIGH7.5

Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

hcltechsw / hcl_commerce+1
Network
Published Jan 12, 2021
CVE-2020-14275
CRITICAL9.8

Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce+2
Network
Published Jan 12, 2021
CVE-2019-4326
HIGH7.5

"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."

hcltech / appscan
Network
Published Oct 6, 2020
CVE-2019-4325
MEDIUM5.3

"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

hcltech / appscan
Network
Published Oct 6, 2020
CVE-2019-4323
MEDIUM4.3

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

hcltech / appscan
Network
Published Jul 7, 2020
CVE-2019-4324
MEDIUM6.1

"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."

hcltech / appscan
Network
Published Jul 7, 2020
CVE-2019-4327
HIGH7.5

"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

hcltech / appscan
Network
Published Apr 21, 2020
CVE-2019-4393
CRITICAL9.8

HCL AppScan Standard is vulnerable to excessive authorization attempts

hcltech / appscan
Network
Published Apr 7, 2020
CVE-2019-4391
HIGH8.2

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

hcltech / appscan
Network
Published Apr 7, 2020
CVE-2019-4392
CRITICAL9.8

HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

hcltech / appscan
Network
Published Feb 14, 2020