Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.25%—Hcltech Devops Plan3/3/202627/7/2026
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
AplazadaMedia (5.9)0.29%—Hcltech ZIE FOR WEBAI23/2/202617/6/2026
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site linked from the application can hijack user…
AnalizadaMedia (4.8)0.16%—Hcltech Digital Experience20/2/202617/6/2026
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
AnalizadaBaja (3.5)0.27%—Hcltech Connections20/2/202617/6/2026
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
AplazadaMedia (6.8)0.29%—HCL VelocityAI7/2/202617/6/2026
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
AnalizadaMedia (5.3)0.21%—Hcltech Aion3/2/202617/6/2026
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.
AnalizadaAlta (8.1)0.24%—Hcltech Aion3/2/202617/6/2026
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.
AnalizadaAlta (8.8)0.23%—Hcltech Aion3/2/202617/6/2026
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
AnalizadaMedia (6.5)0.18%—Hcltech Aion3/2/202617/6/2026
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION: 2.0.
AnalizadaMedia (6.1)0.14%—Hcltech Aion3/2/202617/6/2026
HCL AION is susceptible to Missing Content-Security-Policy. An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.
AnalizadaAlta (7.5)0.18%—Hcltech Aion3/2/202617/6/2026
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.
AnalizadaCrítica (9.8)0.68%—Hcltech Aion3/2/202617/6/2026
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0
AnalizadaMedia (5.3)0.34%—Hcltech Bigfix Compliance28/1/202617/6/2026
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.
AnalizadaCrítica (9.8)0.18%—Hcltech Aion19/1/202617/6/2026
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
AnalizadaMedia (5.3)0.16%—Hcltech Aion19/1/202617/6/2026
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
AnalizadaCrítica (9.8)0.21%—Hcltech Aion19/1/202617/6/2026
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
AnalizadaMedia (5.3)0.20%—Hcltech Aion19/1/202617/6/2026
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.
AnalizadaMedia (5.3)0.18%—Hcltech Aion19/1/202617/6/2026
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
AnalizadaCrítica (9.8)0.33%—Hcltech Aion19/1/202617/6/2026
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
AnalizadaAlta (7.5)0.18%—Hcltech Aion19/1/202617/6/2026
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.
AnalizadaCrítica (9.8)0.27%—Hcltech Myxalytics16/1/202617/6/2026
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
AnalizadaMedia (4.9)0.26%—Hcltechsw HCL Devops Deploy7/1/20267/10/2026
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.
AnalizadaMedia (4.9)0.31%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/20267/10/2026
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
AnalizadaBaja (3.3)0.09%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/20267/10/2026
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
AnalizadaMedia (4.3)0.20%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/20267/10/2026
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Orbitaley — Vulnerabilidades