Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | HCL Unica CampaignAI | 13/10/2025 | 17/6/2026 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website. | |
| Aplazada | Baja (3.5) | 0.50% | — | HCL Unica Maxai WorkbenchAI | 13/10/2025 | 30/9/2026 | HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc. | |
| Analizada | Media (5.3) | 0.21% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers. | |
| Analizada | Media (4.3) | 0.14% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site. | |
| Analizada | Media (6.1) | 0.16% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking. | |
| Aplazada | Media (4.6) | 0.17% | — | HCL Unica Maxai AssistantAI | 12/10/2025 | 17/6/2026 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. | |
| Analizada | Alta (7.5) | 0.26% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application. | |
| Analizada | Alta (7.5) | 0.22% | — | Hcltech Unica Centralized Offer Management | 12/10/2025 | 17/6/2026 | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | |
| Analizada | Crítica (9.8) | 0.24% | — | Hcltech Unica Centralized Offer Management | 12/10/2025 | 17/6/2026 | HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server. | |
| Analizada | Crítica (9.8) | 0.39% | — | Hcltech Unica Centralized Offer Management | 12/10/2025 | 30/9/2026 | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service. | |
| Analizada | Crítica (9.8) | 0.26% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0. | |
| Analizada | Alta (7.5) | 0.24% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0. | |
| Analizada | Media (6.1) | 0.20% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0. | |
| Analizada | Media (6.1) | 0.23% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0 | |
| Analizada | Alta (7.5) | 0.24% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0. | |
| Analizada | Alta (7.5) | 0.15% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0. | |
| Analizada | Alta (7.5) | 0.24% | — | Hcltech Aion | 10/10/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0. | |
| Aplazada | Baja (3.1) | 0.19% | — | HCL MyxalyticsAI | 10/10/2025 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure. | |
| Modificada | Media (4.8) | 0.19% | — | Hcltech Dryice Myxalytics | 3/10/2025 | 17/6/2026 | HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited. | |
| Analizada | Alta (7.6) | 0.25% | — | Hcltech Dryice Myxalytics | 3/10/2025 | 17/6/2026 | HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields. | |
| Modificada | Media (4.6) | 0.18% | — | Hcltech Dryice Myxalytics | 3/10/2025 | 17/6/2026 | HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation. | |
| Analizada | Media (5.4) | 0.26% | — | Hcltech Dryice Myxalytics | 3/10/2025 | 30/9/2026 | HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access. | |
| Aplazada | Alta (7.5) | 0.11% | — | HCL CompassAI | 3/9/2025 | 30/9/2026 | A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access. | |
| Aplazada | Media (5.1) | 0.14% | — | HCL SXAI | 28/8/2025 | 17/6/2026 | AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information. | |
| Aplazada | Media (5.4) | 0.21% | — | HCL Bigfix SMAI | 28/8/2025 | 25/9/2026 | A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts, executables, or web shells, by… |