Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2022-44759 HCL Leap is affected by Cross-site scripting (XSS) — HCL Leap CWE-79 4.6 Medium 2025-04-24
CVE-2022-44760 HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability — HCL Leap CWE-434 4.6 Medium 2025-04-24
CVE-2023-37516 HCL Leap is affected by missing "no cache" headers — HCL Leap CWE-524 3.2 Low 2025-04-24
CVE-2024-30127 HCL Leap is affected by missing "no cache" headers — HCL Leap CWE-524 3.2 Low 2025-04-24
CVE-2023-37534 HCL Leap is affected by a Cross-site scripting (XSS) vulnerability — HCL Leap CWE-79 7.1 High 2025-04-24
CVE-2023-45720 HCL Leap is affected by a disclosure of private personal information vulnerability — HCL Leap CWE-359 5.3 Medium 2025-04-24
CVE-2024-30113 HCL Leap is affected by a cross-site scripting (XSS) vulnerability — HCL Leap CWE-79 6.3 Medium 2025-04-24
CVE-2024-30114 HCL Leap is affected by a cross-site scripting (XSS) vulnerability — HCL Leap CWE-79 3.7 Low 2025-04-24
CVE-2024-30147 HCL Leap is affected by a cross-site scripting (XSS) vulnerability — HCL Leap CWE-79 6.5 Medium 2025-04-24
CVE-2024-30148 HCL Leap is affected by improper access control — HCL Leap CWE-284 4.1 Medium 2025-04-24
CVE-2024-42178 HCL MyXalytics is affected by a failure to restrict URL access vulnerability — HCL MyXalytics CWE-288 2.5 Low 2025-04-17
CVE-2024-42177 HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities — HCL MyXalytics CWE-326 2.6 Low 2025-04-17
CVE-2024-42193 HCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attack — HCL BigFix Platform CWE-295 7.4AI High AI 2025-04-15
CVE-2024-42189 HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack — HCL BigFix Platform CWE-1287 7.5AI High AI 2025-04-15
CVE-2024-42200 HCL BigFix Web Reports is potentially susceptible to a Stored Cross-Site Scripting (XSS) attack — HCL BigFix Platform CWE-79 5.4AI Medium AI 2025-04-15
CVE-2024-42208 HCL Connections is vulnerable to an information disclosure vulnerability — HCL Connections CWE-200 3.5 Low 2025-04-04
CVE-2025-0278 An internal path disclosure vulnerability affects HCL Traveler — HCL Traveler CWE-497 4.3 Medium 2025-04-03
CVE-2025-0279 HCL Traveler is affected by generation of error messages containing sensitive information — HCL Traveler CWE-209 4.3 Medium 2025-04-03
CVE-2025-0272 HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability — HCL DevOps Deploy / HCL Launch CWE-80 5.4 Medium 2025-04-03
CVE-2025-0257 HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services — HCL DevOps Deploy / HCL Launch CWE-306 6.3 Medium 2025-04-02
CVE-2025-0273 HCL DevOps Deploy / HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerability — HCL DevOps Deploy / HCL Launch CWE-532 5.5 Medium 2025-03-27
CVE-2024-30155 HCL SX is susceptible to cookie with Insecure, Improper, or Missing SameSite attribute vulnerability — HCL SX CWE-1275 5.5 Medium 2025-03-26
CVE-2025-0255 HCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerability — HCL DevOps Deploy / HCL Launch CWE-78 7.2 High 2025-03-24
CVE-2025-0256 HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure — HCL DevOps Deploy / HCL Launch CWE-306 4.3 Medium 2025-03-24
CVE-2025-0254 HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. — HCL Digital Experience CWE-295 5.9 Medium 2025-03-20
CVE-2024-42176 HCL MyXalytics is affected by concurrent login vulnerability — HCL MyXalytics 2.6 Low 2025-03-19
CVE-2024-30143 A path traversal vulnerability in HCL AppScan Traffic Recorder — HCL AppScan Traffic Recorder CWE-22 4.3 Medium 2025-03-13
CVE-2024-30154 HCL SX is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability — HCL SX 5.3 Medium 2025-03-03
CVE-2024-30150 An unauthenticated privilege escalation vulnerability affects HCL MyCloud — MyCloud CWE-269 5.3 Medium 2025-02-25
CVE-2024-23563 HCL Connections Docs is vulnerable to a sensitive information disclosure — Connections Docs CWE-200 3.9 Low 2025-02-12

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.