Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.10%—Hcltech Bigfix Service Management28/8/202525/9/2026
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.
AnalizadaMedia (6.5)0.09%—Hcltech Bigfix Service Management28/8/202525/9/2026
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
AnalizadaMedia (4.8)0.24%—Hcltech Digital Experience19/8/202517/6/2026
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
AnalizadaAlta (7.5)0.15%—Hcltech Bigfix Saas15/8/202517/6/2026
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.
AnalizadaMedia (5.4)0.19%—Hcltech Bigfix Saas15/8/202517/6/2026
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
AnalizadaMedia (5.3)0.27%—Hcltech Bigfix Saas15/8/202517/6/2026
HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.
AnalizadaCrítica (9.8)0.33%—Hcltech Bigfix Saas15/8/202517/6/2026
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.
AnalizadaMedia (4.6)0.15%—Hcltech Connections15/8/202517/6/2026
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
AnalizadaAlta (7.5)0.22%—Hcltech Connections Docs14/8/202517/6/2026
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
AplazadaAlta (8.2)0.20%—HCL Bigfix Remote Control ServerAI29/7/202517/6/2026
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.
AnalizadaBaja (2.4)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.
AnalizadaMedia (4.8)0.14%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
AnalizadaMedia (5.7)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.
AnalizadaMedia (4.9)0.18%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
AnalizadaMedia (5.9)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization.
AnalizadaMedia (6.5)0.29%—Hcltech Dryice Iautomate24/7/202517/6/2026
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
AnalizadaMedia (6.5)0.26%—Hcltech Dryice Iautomate24/7/202517/6/2026
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
AnalizadaAlta (7.1)0.33%—Hcltech Dryice Iautomate24/7/202517/6/2026
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
AnalizadaBaja (3.5)0.22%—Hcltech Connections17/7/202517/6/2026
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AplazadaMedia (6.8)0.15%—HCL Glovius CloudAI30/5/202517/6/2026
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs
AnalizadaMedia (5.3)0.31%—Hcltech Bigfix Compliance5/5/202517/6/2026
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
AnalizadaMedia (5.4)0.24%—Hcltech Bigfix Compliance5/5/202517/6/2026
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
AnalizadaBaja (2.7)0.21%—Hcltech Domino Leap30/4/202517/6/2026
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.