Filtered by vendor Hcltech Subscriptions
Total 322 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-52622 1 Hcltech 1 Bigfix Saas 2025-12-04 5.4 Medium
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting (XSS), Clickjacking, and protocol downgrade attacks.
CVE-2025-63401 1 Hcltech 1 Dragon 2025-12-04 5.5 Medium
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
CVE-2025-63402 1 Hcltech 1 Dragon 2025-12-04 5.5 Medium
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
CVE-2025-51736 1 Hcltech 1 Unica 2025-12-02 6.3 Medium
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51735 1 Hcltech 1 Unica 2025-12-02 7.5 High
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51734 1 Hcltech 1 Unica 2025-12-02 5.4 Medium
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51733 1 Hcltech 1 Unica 2025-12-02 5.5 Medium
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-0248 1 Hcltech 1 Hcl Inotes 2025-11-27 8.1 High
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
CVE-2024-23563 1 Hcltech 1 Connections Docs 2025-11-25 3.9 Low
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2025-62346 1 Hcltech 1 Glovius Cloud 2025-11-24 6.8 Medium
A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.
CVE-2025-31987 1 Hcltech 1 Connections Docs 2025-11-21 4.8 Medium
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
CVE-2025-52639 1 Hcltech 1 Connections 2025-11-20 3.5 Low
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.
CVE-2024-30127 1 Hcltech 1 Hcl Leap 2025-11-17 3.2 Low
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2022-44759 1 Hcltech 1 Hcl Leap 2025-11-17 4.6 Medium
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
CVE-2023-37516 1 Hcltech 1 Hcl Leap 2025-11-17 3.2 Low
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
CVE-2022-44760 1 Hcltech 1 Hcl Leap 2025-11-17 4.6 Medium
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
CVE-2024-30147 1 Hcltech 1 Hcl Leap 2025-11-17 6.5 Medium
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114 1 Hcltech 1 Hcl Leap 2025-11-17 3.7 Low
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113 1 Hcltech 1 Hcl Leap 2025-11-17 6.3 Medium
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
CVE-2023-45720 1 Hcltech 1 Hcl Leap 2025-11-17 5.3 Medium
Insufficient default configuration in HCL Leap allows anonymous access to directory information.