Every CVE whose affected-product data names Hcltech Icontrol, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (13)
CVE-2025-52612 — CVSS 7.1 (high): HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability…
CVE-2026-56567 — CVSS 5.1 (medium): HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration…
CVE-2026-56609 — CVSS 4.8 (medium): HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions…
CVE-2025-52606 — CVSS 4.3 (medium): HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural…
CVE-2026-56569 — CVSS 4.0 (medium): HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due…
CVE-2025-52609 — CVSS 3.7 (low): HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the…
CVE-2026-56570 — CVSS 3.7 (low): HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames…
CVE-2026-56571 — CVSS 3.7 (low): HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call…
CVE-2026-56608 — CVSS 3.7 (low): HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls…
CVE-2026-56568 — CVSS 3.7 (low): HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application…
CVE-2025-52608 — CVSS 3.1 (low): HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical…
CVE-2025-62340 — CVSS 3.1 (low): HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application…
CVE-2025-52611 — CVSS 3.1 (low): HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined…