Connections
Vendor:
First CVE: Mar 5, 2020 · Active for 6 years
22
Total CVEs
More Total CVEs than 94% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Connections over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2020
6 years ago
Most Recent CVE
Mar 19, 2026
127 days ago
CVE Severity & Scoring
Connections22 CVEs
14%
86%
All CVEs352,294 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (36.4%)
Unknown0 (0.0%)
Required14 (63.6%)
Privileges Required
Low19 (86.4%)
High0 (0.0%)
None3 (13.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52639MEDIUM HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by impro | Nov 18, 2025 | 6.5 | 22 | NO | NO |
CVE-2019-4209MEDIUM HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. | May 1, 2020 | 6.1 | 22 | NO | NO |
CVE-2026-21788MEDIUM HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user whi | Mar 19, 2026 | 5.4 | 20 | NO | NO |
CVE-2024-30107MEDIUM HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
| Apr 18, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-28018MEDIUM HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerabil | Feb 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2020-4084MEDIUM HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte | Mar 9, 2020 | 5.4 | 19 | NO | NO |
CVE-2020-4083MEDIUM HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. | Mar 5, 2020 | 5.5 | 19 | NO | NO |
CVE-2024-30118MEDIUM HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly han | Oct 9, 2024 | 5.7 | 18 | NO | NO |
CVE-2025-31961MEDIUM HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | Aug 15, 2025 | 4.6 | 17 | NO | NO |
CVE-2024-30112MEDIUM HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user whi | Jun 25, 2024 | 5.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Connections
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 17 | 4.8 | 0.2% | 0 | 0 |
| 7.0 | 13 | 4.9 | 0.3% | 0 | 0 |
| 6.5 | 7 | 6.0 | 0.5% | 0 | 0 |
| 6.0 | 5 | 6.0 | 0.6% | 0 | 0 |
| 5.5 | 4 | 5.8 | 0.7% | 0 | 0 |