Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch17/12/202517/6/2026
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.
AnalizadaMedia (6.1)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch17/12/202530/9/2026
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
AnalizadaMedia (5.6)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch16/12/202517/6/2026
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
AnalizadaMedia (5.9)0.15%—Hcltechsw HCL Devops Deploy16/12/20257/10/2026
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or…
AplazadaMedia (5.5)0.11%—HCL Workload SchedulerAI11/12/20251/10/2026
HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
ModificadaMedia (5.5)0.33%—Hcltech Dragon3/12/20255/7/2026
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
ModificadaMedia (5.5)0.33%—Hcltech Dragon3/12/20255/7/2026
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
AnalizadaMedia (6.3)0.20%—Hcltech Unica28/11/202517/6/2026
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaAlta (7.5)0.34%—Hcltech Unica28/11/202517/6/2026
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaMedia (5.4)0.18%—Hcltech Unica28/11/202517/6/2026
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaMedia (5.5)0.10%—Hcltech Unica28/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AplazadaAlta (8.1)0.38%—HCL InotesAI25/11/202517/6/2026
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's…
AnalizadaMedia (5.5)0.39%—Torrahclef Company Website CMS23/11/202517/6/2026
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.39%—Torrahclef Company Website CMS23/11/202517/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaMedia (6.8)0.11%—HCL Glovius CloudAI20/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.
AnalizadaMedia (6.5)0.21%—Hcltech Connections18/11/202517/6/2026
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.
AplazadaAlta (8.1)0.20%—HCL Devops LoopAI5/11/202517/6/2026
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive…
AnalizadaMedia (4.3)0.19%—Hcltech Dryice Iautomate5/11/202517/6/2026
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
AplazadaMedia (4.2)0.17%—HCL Bigfix QueryAI5/11/202517/6/2026
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can use that information to target individuals with phishing or other social-engineering…
AnalizadaMedia (5.5)0.16%—Hcltech Traveler FOR Microsoft Outlook16/10/20251/10/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
AnalizadaMedia (6.1)0.30%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
AnalizadaMedia (6.1)0.30%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
AnalizadaMedia (4.3)0.26%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
AnalizadaMedia (4.3)0.26%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
AnalizadaAlta (7.5)0.24%—Hcltech Unica13/10/202517/6/2026
HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.
Orbitaley — Vulnerabilidades