VulnSea

hcltech has 12 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. Most affected products: devops_velocity (4), devops_plan (3), bigfix_service_management (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
1 prev 4

Products

  • devops_velocity 4
  • devops_plan 3
  • bigfix_service_management 2
  • dragon 2
  • dfxanalytics 1
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

hcltech vulnerabilities

CVEs affecting hcltech, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-35145Low· 3.1
2mo ago

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker …

Sunlithcltech · dfxanalyticsEPSS 0.27%via NVD
CVE-2026-4096Medium· 6.5
3mo ago

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cros…

Sunlithcltech · devops_planEPSS 0.15%via NVD
CVE-2025-31978Medium· 4.6
4mo ago

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attem…

Sunlithcltech · bigfix_service_managementEPSS 0.14%via NVD
CVE-2025-31976Medium· 4.8
4mo ago

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

Sunlithcltech · bigfix_service_managementEPSS 0.16%via NVD
CVE-2025-31991Medium· 6.8
5mo ago

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

Sunlithcltech · devops_velocityEPSS 0.23%via NVD
CVE-2025-36364Medium· 6.2
6mo ago

IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

Sunlithcltech · devops_planEPSS 0.10%via NVD
CVE-2025-36363Medium· 5.9
6mo ago

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Sunlithcltech · devops_planEPSS 0.24%via NVD
CVE-2025-63402Medium· 5.5
9mo ago

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests

Sunlithcltech · dragonEPSS 0.33%via NVD
CVE-2025-63401Medium· 5.5
9mo ago

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Sunlithcltech · dragonEPSS 0.33%via NVD
CVE-2024-22349Medium· 4.0
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.

Sunlithcltech · devops_velocityEPSS 0.21%via NVD
CVE-2024-22348Medium· 5.3
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is n…

Sunlithcltech · devops_velocityEPSS 0.36%via NVD
CVE-2024-22347Medium· 5.9
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Sunlithcltech · devops_velocityEPSS 0.33%via NVD
hcltech vulnerabilities (CVEs) · VulnSea