Search Results (473 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-21760 1 Hcltech 1 Devops Loop 2026-07-28 4.6 Medium
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
CVE-2026-21761 1 Hcltech 1 Devops Loop 2026-07-28 4.2 Medium
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
CVE-2026-21762 1 Hcltech 1 Devops Loop 2026-07-28 3.7 Low
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.
CVE-2026-21764 1 Hcltech 1 Devops Loop 2026-07-28 3.1 Low
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.
CVE-2026-56584 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.7 Low
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
CVE-2026-56587 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.7 Low
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
CVE-2026-56585 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.1 Low
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
CVE-2026-56586 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.1 Low
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVE-2026-56537 1 Hcltech 1 Connections 2026-07-27 3.5 Low
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.
CVE-2026-56538 1 Hcltech 1 Connections 2026-07-27 3.5 Low
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
CVE-2026-21824 1 Hcltech 1 Commerce 2026-07-23 8.8 High
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
CVE-2026-56459 1 Hcltech 2 Devops Deploy, Launch 2026-07-10 6.2 Medium
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a local user.
CVE-2026-56458 1 Hcltech 1 Devops Deploy 2026-07-10 5.4 Medium
HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
CVE-2026-56460 1 Hcltech 2 Devops Deploy, Launch 2026-07-10 6.5 Medium
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
CVE-2026-56457 1 Hcltech 1 Devops Deploy 2026-06-29 4.3 Medium
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
CVE-2024-23581 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 6.7 Medium
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
CVE-2023-37524 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 7.7 High
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components.
CVE-2025-59868 1 Hcltech 1 Traveler For Microsoft Outlook 2026-06-29 5.5 Medium
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
CVE-2025-59872 1 Hcltech 1 Zie For Web 2026-06-26 4.3 Medium
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2025-15619 1 Hcltech 1 Connections 2026-06-24 3.5 Low
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.