Search Results (508 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-56456 1 Hcltech 1 Dfxanalytics 2026-07-28 5.3 Medium
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.
CVE-2026-56584 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.7 Low
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
CVE-2026-56587 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.7 Low
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
CVE-2026-56585 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.1 Low
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
CVE-2026-56586 1 Hcltech 1 Intelliops Event Management 2026-07-27 3.1 Low
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVE-2026-35146 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 6.3 Medium
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
CVE-2026-35148 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 6.3 Medium
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
CVE-2026-35149 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 8.2 High
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
CVE-2026-35147 2 Hclsoftware, Hcltech 2 Dfxserver, Dfx Server 2026-07-23 8.2 High
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.
CVE-2026-21824 1 Hcltech 1 Commerce 2026-07-23 8.8 High
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
CVE-2023-37508 2 Hclsoftware, Hcltech 2 Devops Plan, Devops Plan 2026-07-23 6.1 Medium
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
CVE-2023-37507 2 Hclsoftware, Hcltech 2 Devops Plan, Devops Plan 2026-07-23 7.5 High
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
CVE-2026-56577 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
CVE-2026-56578 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.2 Low
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.
CVE-2026-56579 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.
CVE-2026-56580 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.2 Low
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.
CVE-2026-56581 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 2.6 Low
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
CVE-2026-56582 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.
CVE-2026-56583 2 Hclsoftware, Hcltech 2 Mycloud, Dryice Mycloud 2026-07-23 3.1 Low
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.
CVE-2026-56459 2 Hcltech, Hcltechsw 4 Devops Deploy, Launch, Hcl Devops Deploy and 1 more 2026-07-10 6.2 Medium
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a local user.