HCL Software
First CVE: Oct 18, 2019Active for: 7 years
563
CVEs Published
More CVEs Published than 87% of tracked CNAs
70.4
Avg CVEs / Year
More Avg CVEs / Year than 87% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by HCL Software as a CNA, 0.7% affect products that HCL Software develops as a vendor.
99.3%
Self-reported: 4Third-party: 559
Of all the CVEs published that affect products developed by HCL Software, 100.0% are self-published by HCL Software as a CNA.
100.0%
Self-published: 4Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by HCL Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2019
6 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by HCL Software as a CNA, regardless of affected vendor or product.
563 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23564CRITICAL HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own | Jul 17, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-56453CRITICAL HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses b | Jul 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-21824HIGH HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative oper | Jul 20, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35149HIGH HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by interc | Jul 16, 2026 | 8.2 | 36 | NO | NO |
CVE-2025-59872CRITICAL HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the se | Jun 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-21837HIGH HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typic | Jun 5, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-35147HIGH HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific A | Jul 16, 2026 | 8.2 | 35 | NO | NO |
CVE-2024-23581HIGH The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | Jun 26, 2026 | 7.8 | 35 | NO | NO |
CVE-2025-31973CRITICAL HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabili | May 20, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-55251CRITICAL HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA563 CVEs
10%
57%
23%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local69 (12.3%)
Network477 (84.7%)
Unknown0 (0.0%)
Physical4 (0.7%)
Adjacent Network13 (2.3%)
Attack Complexity
Low489 (86.9%)
High74 (13.1%)
Unknown0 (0.0%)
User Interaction
None350 (62.2%)
Unknown0 (0.0%)
Required212 (37.7%)
Privileges Required
Low207 (36.8%)
High45 (8.0%)
None311 (55.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (563 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by HCL Software as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HCL Software as a CNA — matched by CVE ID, not by organization name.