Every CVE whose affected-product data names Hcltech Devops Plan, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2023-37507 — CVSS 7.5 (high): HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information…
CVE-2026-4096 — CVSS 6.5 (medium): IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers…
CVE-2025-36364 — CVSS 6.2 (medium): IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
CVE-2023-37508 — CVSS 6.1 (medium): HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if…
CVE-2025-36363 — CVSS 5.9 (medium): IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account…