HCL Software maintains a narrow portfolio focused on enterprise application and collaboration platforms, notably AION and the Domino AppDev Pack, where its documented vulnerabilities center on input-handling and cryptographic-verification weaknesses such as SQL injection and signature-validation gaps. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by HCL Software over time
Of all the CVEs published by HCL Software as a CNA, 0.7% affect products that HCL Software develops as a vendor.
Of all the CVEs published that affect products developed by HCL Software, 100.0% are self-published by HCL Software as a CNA.
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52648CRITICAL HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leadin | Mar 16, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-52638HIGH HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potenti | Mar 16, 2026 | 7.2 | 23 | NO | NO |
CVE-2025-52637HIGH HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query | Mar 16, 2026 | 7.3 | 23 | NO | NO |
CVE-2023-28015MEDIUM The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker | May 23, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by HCL Software.
Media articles that mention a CVE ID that affects a product developed by HCL Software — matched by CVE ID, not by vendor name.