HCL Software

First CVE: Oct 18, 2019Active for: 7 years
563
CVEs Published
More CVEs Published than 87% of tracked CNAs
70.4
Avg CVEs / Year
More Avg CVEs / Year than 87% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by HCL Software as a CNA, 0.7% affect products that HCL Software develops as a vendor.

99.3%
Self-reported: 4Third-party: 559

Of all the CVEs published that affect products developed by HCL Software, 100.0% are self-published by HCL Software as a CNA.

100.0%
Self-published: 4Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by HCL Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2019
6 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by HCL Software as a CNA, regardless of affected vendor or product.

563 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own
Jul 17, 20269.138NONO
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses b
Jul 16, 20269.838NONO
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative oper
Jul 20, 20268.837NONO
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by interc
Jul 16, 20268.236NONO
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the se
Jun 17, 20269.836NONO
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typic
Jun 5, 20268.836NONO
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific A
Jul 16, 20268.235NONO
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Jun 26, 20267.835NONO
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabili
May 20, 20269.834NONO
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Jan 19, 20269.834NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA563 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local69 (12.3%)
Network477 (84.7%)
Unknown0 (0.0%)
Physical4 (0.7%)
Adjacent Network13 (2.3%)
Attack Complexity
Low489 (86.9%)
High74 (13.1%)
Unknown0 (0.0%)
User Interaction
None350 (62.2%)
Unknown0 (0.0%)
Required212 (37.7%)
Privileges Required
Low207 (36.8%)
High45 (8.0%)
None311 (55.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (563 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by HCL Software as a CNA.

Media Mentions

Media articles that mention a CVE ID published by HCL Software as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs