Search Results (38 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-35148 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 6.3 Medium
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
CVE-2026-35149 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 8.2 High
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
CVE-2026-35147 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 8.2 High
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.
CVE-2023-37508 2 Hclsoftware, Hcltech 2 Devops Plan, Devops Plan 2026-07-23 6.1 Medium
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
CVE-2023-37507 2 Hclsoftware, Hcltech 2 Devops Plan, Devops Plan 2026-07-23 7.5 High
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
CVE-2026-56577 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
CVE-2026-56578 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.2 Low
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.
CVE-2026-56579 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.
CVE-2026-56580 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.2 Low
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.
CVE-2026-56581 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.6 Low
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
CVE-2026-56582 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.
CVE-2026-56583 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.
CVE-2026-21768 1 Hclsoftware 1 Verse For Android 2026-06-22 6.3 Medium
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
CVE-2026-21836 1 Hclsoftware 1 Dominoiq 2026-05-21 6.5 Medium
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable an authenticated attacker to view sensitive data.
CVE-2026-21821 1 Hclsoftware 1 Bigfix Scm Reporting 2026-05-14 8.3 High
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site Scripting (XSS) or manipulation through vulnerable third-party components.
CVE-2025-31991 2 Hclsoftware, Hcltech 2 Velocity, Devops Velocity 2026-04-17 6.8 Medium
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.
CVE-2026-21786 2 Hclsoftware, Hcltech 2 Sametime For Ios, Sametime 2026-04-16 3.3 Low
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
CVE-2025-31990 1 Hclsoftware 1 Hcl Devops Velocity 2026-04-15 6.8 Medium
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.