Hcl Commerce
8 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Hcl Commerce, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Hcl Commerce CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High3
- Medium2
- Low1
Latest CVEs
The 8 most recently published vulnerabilities affecting Hcl Commerce.
- CVE-2024-23576HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability7.1
- CVE-2023-37532A path traversal vulnerability affects HCL Commerce5.8
- CVE-2022-38656HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability8.6
- CVE-2021-27785HCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785)3.9
- CVE-2021-27751HCL Commerce is affected by an Insufficient Session Expiration vulnerability.4.4
- CVE-2021-27741" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"9.1
- CVE-2020-14274Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.7.5
- CVE-2020-14275Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of un...9.8
Product grouping is registry-driven, with AI assist and human review. How it works