Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HCLSoftware — Vulnerabilities & Security Advisories 86

Browse all 86 CVE security advisories affecting HCLSoftware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCLSoftware develops enterprise software solutions including application development, integration, and digital experience platforms. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control flaws. With 19 CVEs currently on record, security researchers have identified consistent patterns in their codebase. While no major public security incidents have been widely documented, the volume of disclosed vulnerabilities suggests ongoing challenges in secure coding practices. Organizations implementing HCLSoftware solutions should prioritize regular patching and hardening of these environments to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2025-68825 HCL Hive is affected by incorrect default permissions — HCL Hive CWE-276 7.5 High 2026-08-24
CVE-2026-21752 HCL Hive is affected by a use of vulnerable third-party components — HCL Hive CWE-1104 7.5 High 2026-08-24
CVE-2026-21755 HCL Hive is affected by a missing rate limit — HCL Hive CWE-307 5.3 Medium 2026-08-24
CVE-2025-68833 HCL Hive is affected by use of a cryptographic primitive with a risky implementation — HCL Hive CWE-1240 5.3 Medium 2026-08-24
CVE-2026-21751 HCL Hive is affected by use of a cryptographic primitive with a risky implementation — HCL Hive CWE-1240 7.4 High 2026-08-24
CVE-2026-21756 HCL Hive is affected by a broken access control vulnerability — HCL Hive CWE-266 7.2 High 2026-08-24
CVE-2026-21759 HCL Hive is affected by an information exposure vulnerability — HCL Hive CWE-215 4.3 Medium 2026-08-24
CVE-2026-56619 HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) — HCL BigFix Mobile CWE-79 5.4 Medium 2026-08-10
CVE-2026-56620 HCL BigFix Mobile is vulnerable to information disclosure — HCL BigFix Mobile CWE-209 4.3 Medium 2026-08-10
CVE-2026-21766 HCL Digital Experience and Digital Experience Compose insufficiently protects credentials — HCL Digital Experience and Digital Experience Compose CWE-522 5.4 Medium 2026-08-05
CVE-2026-56538 HCL Connections is vulnerable to information disclosure — Connections CWE-213 3.5 Low 2026-07-27
CVE-2026-56537 HCL Connections is vulnerable to information disclosure — Connections CWE-209 3.5 Low 2026-07-27
CVE-2026-56583 HCL MyCloud was affected with Concurrent Login Vulnerability. — MyCloud CWE-613 3.1 Low 2026-07-21
CVE-2026-56582 HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability. — MyCloud CWE-327 3.1 Low 2026-07-21
CVE-2026-56581 HCL MyCloud was affected with Cookie Attribute Path Not Set — MyCloud CWE-614 2.6 Low 2026-07-21
CVE-2026-56580 HCL MyCloud was affected by Using Components with Known Vulnerability — MyCloud CWE-1104 2.2 Low 2026-07-21
CVE-2026-56579 HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor. — MyCloud CWE-200 3.1 Low 2026-07-21
CVE-2026-56578 HCL MyCloud was affected by Server Version Disclosure — MyCloud CWE-200 2.2 Low 2026-07-21
CVE-2026-56577 HCL MyCloud affected by Weak Password Policy — MyCloud CWE-521 3.1 Low 2026-07-21
CVE-2026-56586 HCL IEM was affected with X-Content-Type-Options Header Missing — IntelliOps Event Management CWE-16 3.1 Low 2026-07-21
CVE-2026-56585 HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing — IntelliOps Event Management CWE-693 3.1 Low 2026-07-21
CVE-2026-56587 HCL IEM was affected with Strict transport security not enforced — IntelliOps Event Management CWE-523 3.7 Low 2026-07-21
CVE-2026-56584 HCL IEM was affected with the Information disclosure nginx server — IntelliOps Event Management CWE-200 3.7 Low 2026-07-21
CVE-2023-37507 An information disclosure vulnerability affects HCL DevOps Plan — DevOps Plan CWE-497 - - 2026-07-21
CVE-2023-37508 HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability — DevOps Plan CWE-79 - - 2026-07-21
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce — Commerce CWE-266 8.8 High 2026-07-20
CVE-2025-59866 HCLSoftware DFMPro for CATIA 权限许可和访问控制问题漏洞 — DFMPro for CATIA CWE-732 3.3 Low 2026-07-17
CVE-2026-21764 Insufficient Input Validation in DevOps Loop — DevOps Loop CWE-754 3.1 Low 2026-07-17
CVE-2026-21762 Missing HTTP Security Headers in DevOps Loop — DevOps Loop CWE-644 3.7 Low 2026-07-17
CVE-2026-21761 CORS Misconfiguration in DevOps Loop — DevOps Loop CWE-942 4.2 Medium 2026-07-17

This page lists every published CVE security advisory associated with HCLSoftware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.