Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.23% | — | Hcltech Bigfix Platform | 15/4/2025 | 17/6/2026 | HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input. | |
| Analizada | Media (5.6) | 0.30% | — | Hcltech Bigfix Platform | 15/4/2025 | 17/6/2026 | HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter. | |
| Analizada | Baja (3.5) | 0.27% | — | Hcltech Connections | 4/4/2025 | 17/6/2026 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | |
| Analizada | Media (4.3) | 0.30% | — | Hcltech Traveler | 3/4/2025 | 17/6/2026 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch… | |
| Analizada | Media (4.3) | 0.30% | — | Hcltech Traveler | 3/4/2025 | 17/6/2026 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. | |
| Analizada | Alta (7.6) | 0.26% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 3/4/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | |
| Analizada | Alta (7.5) | 0.31% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 2/4/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. | |
| Analizada | Media (5.5) | 0.15% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 27/3/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. | |
| Analizada | Media (4.3) | 0.22% | — | Hcltech HCL SX | 26/3/2025 | 17/6/2026 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF). | |
| Analizada | Alta (7.2) | 0.68% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 24/3/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. | |
| Analizada | Media (6.5) | 0.27% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 24/3/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. | |
| Aplazada | Media (5.9) | 0.29% | — | HCL Digital ExperienceAIHCL Ring APIAIHCL DxclientAI | 20/3/2025 | 17/6/2026 | HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties. | |
| Analizada | Alta (8) | 0.22% | — | Hcltech Dryice Myxalytics | 19/3/2025 | 17/6/2026 | HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information. | |
| Aplazada | Media (4.3) | 0.40% | — | HCL Appscan Traffic RecorderAI | 13/3/2025 | 17/6/2026 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the application is running. | |
| Analizada | Media (5.7) | 0.15% | — | Hcltech HCL SX | 3/3/2025 | 17/6/2026 | HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Crítica (9.1) | 0.35% | — | Hcltech Dryice Mycloud | 25/2/2025 | 17/6/2026 | HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users. | |
| Analizada | Media (4.4) | 0.15% | — | Hcltech Connections Docs | 12/2/2025 | 17/6/2026 | HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | |
| Analizada | Media (6) | 0.28% | — | Hcltech Dryice Iautomate | 5/2/2025 | 17/6/2026 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session. | |
| Analizada | Baja (3.3) | 0.21% | — | Hcltech Devops VelocityIBM Urbancode Velocity | 20/1/2025 | 27/7/2026 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system. | |
| Analizada | Alta (7.5) | 0.36% | — | Hcltech Devops VelocityIBM Urbancode Velocity | 20/1/2025 | 27/7/2026 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. | |
| Analizada | Alta (7.5) | 0.33% | — | Hcltech Devops VelocityIBM Urbancode Velocity | 20/1/2025 | 27/7/2026 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Alta (7.5) | 0.18% | — | Hcltech Dryice Myxalytics | 12/1/2025 | 17/6/2026 | HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | |
| Analizada | Crítica (9.8) | 0.26% | — | Hcltech Dryice Myxalytics | 12/1/2025 | 17/6/2026 | HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files. | |
| Analizada | Baja (2.7) | 0.23% | — | Hcltech Dryice Myxalytics | 12/1/2025 | 17/6/2026 | HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version. | |
| Analizada | Crítica (9.8) | 0.28% | — | Hcltech Dryice Myxalytics | 11/1/2025 | 17/6/2026 | HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like SQL injection, XSS, and buffer overflow. |