Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.36%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch15/4/202417/6/2026
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
AnalizadaMedia (6.3)0.31%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch15/4/202417/6/2026
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
AnalizadaMedia (4.9)0.32%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch15/4/202417/6/2026
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
AnalizadaMedia (6.1)0.31%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch15/4/202417/6/2026
HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
AnalizadaCrítica (9.8)0.56%—Hcltech Dryice Myxalytics10/4/202417/6/2026
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.
AplazadaMedia (5.3)0.58%—HCL Bigfix InventoryAI3/4/202417/6/2026
The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.
AnalizadaMedia (4.3)0.40%—Hcltech Bigfix Platform28/3/202417/6/2026
The console may experience a service interruption when processing file names with invalid characters.
AnalizadaMedia (4)0.26%—Hcltech Bigfix Platform28/3/202417/6/2026
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.
ModificadaAlta (7.2)0.37%—Hcltech Bigfix Platform28/3/202417/6/2026
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
ModificadaMedia (4.8)0.36%—Hcltech Bigfix Platform29/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
ModificadaMedia (5.4)0.34%—Hcltech Bigfix Platform29/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
ModificadaMedia (5.4)0.34%—Hcltech Bigfix Platform29/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
AnalizadaMedia (5.9)0.47%—Hcltech Domino29/2/202417/6/2026
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password,…
AnalizadaBaja (3.9)0.18%—Hcltech Sametime23/2/202417/6/2026
Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.
ModificadaMedia (6.5)0.32%—Hcltech Connections12/2/202417/6/2026
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
ModificadaMedia (6.1)0.32%—Hcltech Sametime Chat AND Meetings10/2/202417/6/2026
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
ModificadaAlta (7.5)0.44%—Hcltech Sametime10/2/202417/6/2026
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
ModificadaAlta (7.5)0.35%—Hcltech Sametime9/2/202417/6/2026
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.
ModificadaMedia (4.1)0.12%—Hcltech Sametime9/2/202417/6/2026
Sametime is impacted by sensitive information passed in URL.
ModificadaAlta (8.8)0.24%—Hcltech Sametime9/2/202417/6/2026
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
ModificadaMedia (5.5)0.21%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch3/2/202417/6/2026
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
ModificadaMedia (6.1)0.34%—Hcltech Bigfix Platform3/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
ModificadaMedia (5.4)0.26%—Hcltech Bigfix Platform2/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
ModificadaMedia (6.1)0.36%—Hcltech Bigfix Platform2/2/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
ModificadaAlta (8.8)0.40%—Hcltech Bigfix Servicenow Data Flow30/1/202417/6/2026
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
Orbitaley — Vulnerabilidades