LIVE · cybersecurity feed
Live wire
vendor

Hcltech

18 CVEs published in the last four months. Exploited flaws first.

Critical1
High7
Medium4
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2025-623199.8criticalunicaBoolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injectin173d ago
CVE-2026-218378.8highdigital experienceHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.92d ago
CVE-2026-351498.2highdfx serverHCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.51d ago
CVE-2026-351478.2highdfx serverHCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.51d ago
CVE-2023-375247.7hightraveler for microsoft outlookHCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of70d ago
CVE-2024-422107.6highunicaA Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.170d ago
CVE-2023-375077.5highdevops planHCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks base46d ago
CVE-2025-526127.1highicontrolHCL iControl was affected by Export CSV - CSV Injection vulnerability.93d ago
CVE-2025-526445.8mediumaionHCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.173d ago
CVE-2026-217885.4mediumconnectionsHCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execut170d ago
CVE-2025-623204.7mediumunicaHTML Injection can be carried out in Product when a web application does not properly check or clean user input be172d ago
CVE-2025-526434.7mediumaionHCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly173d ago
CVE-2025-526423.3lowaionHCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application respons173d ago
CVE-2025-319662.7lowsametimeHCL Sametime is vulnerable to broken server-side validation.172d ago
CVE-2025-526462.2lowaionHCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially 173d ago
CVE-2025-526451.9lowaionHCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficie173d ago
CVE-2025-526491.8lowaionHCL AION is affected by a vulnerability where certain identifiers may be predictable in nature.173d ago
CVE-2025-526361.8lowaionHCL AION is affected by a vulnerability related to the handling of upload size limits.173d ago

Filter the full tracker by Hcltech