CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “hcltechsw”

47 vulnerabilities found for “hcltechsw”

Page 1 of 3

CVE-2024-42195
LOW3.1

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

hcltechsw / hcl_devops_deploy+4
Network
Published Dec 5, 2024
Page 1 of 3
CVE-2024-23576
HIGH7.1

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce
Network
Published May 14, 2024
CVE-2024-23559
MEDIUM6.1

HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

hcltechsw / hcl_devops_deploy+4
Network
Published Apr 15, 2024
CVE-2024-23560
MEDIUM4.4

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

hcltechsw / hcl_devops_deploy+4
Network
Published Apr 15, 2024
CVE-2024-23558
MEDIUM6.3

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

hcltechsw / hcl_devops_deploy+4
Network
Published Apr 15, 2024
CVE-2024-23561
MEDIUM4.3

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

hcltechsw / hcl_devops_deploy+4
Network
Published Apr 15, 2024
CVE-2024-23550
MEDIUM6.2

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

hcltechsw / hcl_devops_deploy+4
Local
Published Feb 3, 2024
CVE-2023-37522
MEDIUM5.6

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.

hcltechsw / bigfix_bare_osd_metal_server_webui
Network
Published Jan 16, 2024
CVE-2023-37523
MEDIUM5.6

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.

hcltechsw / bigfix_bare_osd_metal_server_webui
Network
Published Jan 16, 2024
CVE-2023-37521
LOW2.3

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.

hcltechsw / bigfix_bare_osd_metal_server_webui
Local
Published Jan 16, 2024
CVE-2022-38656
HIGH8.6

HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

hcltechsw / hcl_commerce
Network
Published Dec 12, 2022
CVE-2022-38661
MEDIUM6.2

HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.

hcltechsw / hcl_workload_automation+1
Local
Published Dec 12, 2022
CVE-2021-27785
LOW3.9

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

hcltechsw / hcl_commerce+1
Physical
Published Jul 30, 2022
CVE-2021-27751
MEDIUM4.4

HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

hcltechsw / hcl_commerce+2
Local
Published May 6, 2022
CVE-2021-27741
CRITICAL9.1

" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

hcltechsw / hcl_commerce+2
Network
Published Aug 13, 2021
CVE-2020-14275
CRITICAL9.8

Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce+2
Network
Published Jan 12, 2021
CVE-2020-14274
HIGH7.5

Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

hcltechsw / hcl_commerce+1
Network
Published Jan 12, 2021
CVE-2020-14231
HIGH8.8

A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.

hcltechsw / hcl_client_application_access
Network
Published Dec 22, 2020
CVE-2020-14225
MEDIUM6.5

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

hcltech / hcl_inotes+9
Network
Published Dec 21, 2020
CVE-2020-4100
MEDIUM4.4

"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly."

hcltechsw / hcl_verse
Local
Published Jul 15, 2020