Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.68% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 24/3/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. | |
| Analizada | Media (6.5) | 0.27% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 24/3/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. | |
| Analizada | Alta (7.2) | 0.69% | — | IBM Devops DeployIBM Urbancode Deploy | 14/2/2025 | 17/6/2026 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing… | |
| Analizada | Media (6.5) | 0.28% | — | IBM Devops DeployIBM Urbancode Deploy | 8/2/2025 | 17/6/2026 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. | |
| Analizada | Baja (3.1) | 0.25% | — | IBM Devops DeployIBM Urbancode Deploy | 6/1/2025 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | |
| Analizada | Media (6.8) | 0.29% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 5/12/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | |
| Analizada | Media (5.4) | 0.28% | — | IBM Devops DeployIBM Urbancode Deploy | 14/5/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… | |
| Analizada | Media (4.3) | 0.36% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. | |
| Analizada | Media (6.3) | 0.31% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.9) | 0.32% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | |
| Analizada | Media (6.1) | 0.31% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. | |
| Analizada | Media (6.1) | 0.37% | — | IBM Devops DeployIBM Urbancode Deploy | 12/4/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… | |
| Analizada | Alta (8.8) | 0.41% | — | IBM Devops DeployIBM Urbancode Deploy | 12/4/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 280896. | |
| Analizada | Media (4.3) | 0.44% | — | IBM Devops DeployIBM Urbancode Deploy | 12/4/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM X-Force ID: 279979. | |
| Analizada | Media (4.4) | 0.44% | — | IBM Devops DeployIBM Urbancode Deploy | 12/4/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. When deleting a custom security type, associated… | |
| Modificada | Media (5.5) | 0.19% | — | IBM Urbancode DeployIBM Devops Deploy | 6/2/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971. | |
| Modificada | Media (5.5) | 0.21% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 3/2/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. |