Connections

Vendor:

First CVE: Mar 5, 2020 · Active for 6 years

22
Total CVEs
More Total CVEs than 94% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Connections over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2020
6 years ago
Most Recent CVE
Mar 19, 2026
127 days ago

CVE Severity & Scoring

Connections22 CVEs
All CVEs352,294 CVEs
LowMedium
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (36.4%)
Unknown0 (0.0%)
Required14 (63.6%)
Privileges Required
Low19 (86.4%)
High0 (0.0%)
None3 (13.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by impro
Nov 18, 20256.522NONO
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
May 1, 20206.122NONO
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user whi
Mar 19, 20265.420NONO
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
Apr 18, 20246.519NONO
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerabil
Feb 12, 20246.519NONO
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte
Mar 9, 20205.419NONO
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
Mar 5, 20205.519NONO
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly han
Oct 9, 20245.718NONO
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
Aug 15, 20254.617NONO
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user whi
Jun 25, 20245.417NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Connections

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0174.80.2%00
7.0134.90.3%00
6.576.00.5%00
6.056.00.6%00
5.545.80.7%00