Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hcltech

First CVE: May 30, 2018Active for: 8 yearsTotal CVEs: 427
21.1
VTI Score
Low

HCLtech's vulnerability footprint spans a moderately broad portfolio of enterprise software products including system management, business intelligence, and collaboration platforms such as BigFix Platform, DryIce MyXalytics, AION, Domino, and Connections, positioning the vendor prominently in business-critical and development environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the complexity and integration demands of large enterprise middleware and application-server codebases. The exposure recurs through web-application and information-disclosure weakness classes, including cross-site scripting, cross-site request forgery, improper input neutralization, and sensitive information exposure, which are characteristic of widely deployed server platforms where authentication and request validation are central. Defenders should prioritize HCLtech advisories for products connected to identity, configuration management, or inter-system integration, as these are high-value targets for lateral movement. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
427
Total CVEs
More Total CVEs than 100% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hcltech over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2018
8 years ago
Most Recent CVE
Jul 21, 2026
4 days ago

Products(96 total)

Top CVEs

Signals from CVEs in this vendor scope (427 CVEs).

427 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-56453CRITICAL
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses b
Jul 16, 20269.838NONO
CVE-2025-31973CRITICAL
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabili
May 20, 20269.837NONO
CVE-2026-35149HIGH
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by interc
Jul 16, 20268.236NONO
CVE-2025-59872CRITICAL
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the se
Jun 17, 20269.836NONO
CVE-2026-21837HIGH
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typic
Jun 5, 20268.836NONO
CVE-2026-35147HIGH
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific A
Jul 16, 20268.235NONO
CVE-2024-23581HIGH
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Jun 26, 20267.835NONO
CVE-2025-55251CRITICAL
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Jan 19, 20269.834NONO
CVE-2026-35142HIGH
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which c
Jul 16, 20268.233NONO
CVE-2023-37524HIGH
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and no
Jun 27, 20267.833NONO
View all 427 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products427 CVEs
57%
27%
11%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local44 (10.3%)
Network378 (88.5%)
Unknown0 (0.0%)
Physical4 (0.9%)
Adjacent Network1 (0.2%)
Attack Complexity
Low402 (94.1%)
High25 (5.9%)
Unknown0 (0.0%)
User Interaction
None270 (63.2%)
Unknown0 (0.0%)
Required157 (36.8%)
Privileges Required
Low141 (33.0%)
High31 (7.3%)
None255 (59.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (427 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hcltech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hcltech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hcltech's Products

View all 3 CNAs →

Top CWEs