CVE-2025-52656
- EPSS 0.03%
- Published 03.10.2025 18:20:18
- Last modified 08.10.2025 16:50:39
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of s...
CVE-2025-52658
- EPSS 0.03%
- Published 03.10.2025 18:16:00
- Last modified 08.10.2025 16:50:52
HCL MyXalytics 6.6. product is affected by Use of Vulnerable/Outdated Versions Vulnerability
CVE-2025-52654
- EPSS 0.03%
- Published 03.10.2025 18:11:20
- Last modified 08.10.2025 16:50:47
A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.
CVE-2025-52653
- EPSS 0.05%
- Published 03.10.2025 17:59:44
- Last modified 08.10.2025 16:50:59
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.
CVE-2024-42178
- EPSS 0.07%
- Published 17.04.2025 21:24:34
- Last modified 16.05.2025 13:44:58
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.
CVE-2024-42177
- EPSS 0.02%
- Published 17.04.2025 19:18:05
- Last modified 16.05.2025 13:45:01
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the s...
- EPSS 0.04%
- Published 19.03.2025 14:24:21
- Last modified 16.05.2025 13:45:03
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensi...
CVE-2024-42181
- EPSS 0.05%
- Published 12.01.2025 22:15:07
- Last modified 16.05.2025 13:45:05
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVE-2024-42180
- EPSS 0.2%
- Published 12.01.2025 22:15:06
- Last modified 16.05.2025 13:45:08
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute mal...
CVE-2024-42179
- EPSS 0.08%
- Published 12.01.2025 22:15:05
- Last modified 16.05.2025 13:49:41
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.