Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HCLSoftware — Vulnerabilities & Security Advisories 79

Browse all 79 CVE security advisories affecting HCLSoftware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCLSoftware develops enterprise software solutions including application development, integration, and digital experience platforms. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control flaws. With 19 CVEs currently on record, security researchers have identified consistent patterns in their codebase. While no major public security incidents have been widely documented, the volume of disclosed vulnerabilities suggests ongoing challenges in secure coding practices. Organizations implementing HCLSoftware solutions should prioritize regular patching and hardening of these environments to mitigate potential exploitation risks.

CVE IDTitleCVSSSeverityPublished
CVE-2026-56619 HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) — HCL BigFix MobileCWE-79 5.4 Medium2026-08-10
CVE-2026-56620 HCL BigFix Mobile is vulnerable to information disclosure — HCL BigFix MobileCWE-209 4.3 Medium2026-08-10
CVE-2026-21766 HCL Digital Experience and Digital Experience Compose insufficiently protects credentials — HCL Digital Experience and Digital Experience ComposeCWE-522 5.4 Medium2026-08-05
CVE-2026-56538 HCL Connections is vulnerable to information disclosure — ConnectionsCWE-213 3.5 Low2026-07-27
CVE-2026-56537 HCL Connections is vulnerable to information disclosure — ConnectionsCWE-209 3.5 Low2026-07-27
CVE-2026-56583 HCL MyCloud was affected with Concurrent Login Vulnerability. — MyCloudCWE-613 3.1 Low2026-07-21
CVE-2026-56582 HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability. — MyCloudCWE-327 3.1 Low2026-07-21
CVE-2026-56581 HCL MyCloud was affected with Cookie Attribute Path Not Set — MyCloudCWE-614 2.6 Low2026-07-21
CVE-2026-56580 HCL MyCloud was affected by Using Components with Known Vulnerability — MyCloudCWE-1104 2.2 Low2026-07-21
CVE-2026-56579 HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor. — MyCloudCWE-200 3.1 Low2026-07-21
CVE-2026-56578 HCL MyCloud was affected by Server Version Disclosure — MyCloudCWE-200 2.2 Low2026-07-21
CVE-2026-56577 HCL MyCloud affected by Weak Password Policy — MyCloudCWE-521 3.1 Low2026-07-21
CVE-2026-56586 HCL IEM was affected with X-Content-Type-Options Header Missing — IntelliOps Event ManagementCWE-16 3.1 Low2026-07-21
CVE-2026-56585 HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing — IntelliOps Event ManagementCWE-693 3.1 Low2026-07-21
CVE-2026-56587 HCL IEM was affected with Strict transport security not enforced — IntelliOps Event ManagementCWE-523 3.7 Low2026-07-21
CVE-2026-56584 HCL IEM was affected with the Information disclosure nginx server — IntelliOps Event ManagementCWE-200 3.7 Low2026-07-21
CVE-2023-37507 An information disclosure vulnerability affects HCL DevOps Plan — DevOps PlanCWE-497--2026-07-21
CVE-2023-37508 HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability — DevOps PlanCWE-79--2026-07-21
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce — CommerceCWE-266 8.8 High2026-07-20
CVE-2025-59866 HCLSoftware DFMPro for CATIA 权限许可和访问控制问题漏洞 — DFMPro for CATIACWE-732 3.3 Low2026-07-17
CVE-2026-21764 Insufficient Input Validation in DevOps Loop — DevOps LoopCWE-754 3.1 Low2026-07-17
CVE-2026-21762 Missing HTTP Security Headers in DevOps Loop — DevOps LoopCWE-644 3.7 Low2026-07-17
CVE-2026-21761 CORS Misconfiguration in DevOps Loop — DevOps LoopCWE-942 4.2 Medium2026-07-17
CVE-2026-21760 Unauthorized Access to Admin Functionality via Forced Browsing — DevOps LoopCWE-425 4.6 Medium2026-07-17
CVE-2024-23572 HCL Aftermarket EPC 会话机制问题漏洞 — Aftermarket EPCCWE-614 4.2 Medium2026-07-17
CVE-2024-23570 HCL Aftermarket EPC 信息泄露漏洞 — Aftermarket EPCCWE-200 4.3 Medium2026-07-17
CVE-2024-23578 HCL Aftermarket EPC 配置错误漏洞 — Aftermarket EPCCWE-942 4.2 Medium2026-07-17
CVE-2024-23569 HCL Aftermarket EPC 跨站脚本漏洞 — Aftermarket EPCCWE-692 4.3 Medium2026-07-17
CVE-2024-23577 HCL Aftermarket EPC 输入验证错误漏洞 — Aftermarket EPCCWE-20 4.3 Medium2026-07-17
CVE-2024-23574 HCL Aftermarket EPC 侧信道信息泄露漏洞 — Aftermarket EPCCWE-204 5.3 Medium2026-07-17

This page lists every published CVE security advisory associated with HCLSoftware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.