Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.38%—HCL Devops DeployAIHCL LaunchAI17/9/202618/9/2026
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside…
Pendiente de análisisBaja (3.5)0.16%—HCL MyxalyticsAI7/9/20268/9/2026
HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.
Pendiente de análisisBaja (3.5)0.15%—HCL MyxalyticsAI7/9/20268/9/2026
HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.
Pendiente de análisisBaja (3.5)0.15%—HCL MyxalyticsAI7/9/20268/9/2026
HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.
Pendiente de análisisBaja (3.1)0.15%—HCL ConnectionsAI31/8/20263/9/2026
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
AplazadaBaja (3.1)0.18%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
AplazadaMedia (6.4)0.19%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.
Pendiente de análisisMedia (4.1)0.10%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
Pendiente de análisisBaja (3.9)0.09%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
AplazadaBaja (3.7)0.12%—HCL ConnectionsAI26/8/202628/8/2026
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
Pendiente de análisisMedia (4.4)0.07%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
Pendiente de análisisBaja (3.9)0.09%—HCL Bigfix Quantum Risk AnalyzerAI26/8/202628/8/2026
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
AplazadaBaja (3.5)0.28%—Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI26/8/202628/8/2026
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the…
AplazadaBaja (3.7)0.17%—HCL HiveAI25/8/202628/9/2026
HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.
AplazadaMedia (5.4)0.14%—HCL HiveAI25/8/202628/9/2026
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.
AplazadaMedia (4.2)0.14%—HCL HiveAI25/8/202628/9/2026
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
AplazadaAlta (7.5)0.27%—HCL HiveAI24/8/202628/8/2026
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.
AplazadaMedia (5.3)0.21%—HCL HiveAI24/8/202628/8/2026
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.
AplazadaAlta (7.5)0.23%—HCL HiveAI24/8/202629/9/2026
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
AplazadaAlta (7.4)0.16%—HCL HiveAI24/8/202628/8/2026
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.
AplazadaMedia (4.3)0.22%—HCL HiveAI24/8/202628/8/2026
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.
AplazadaAlta (7.2)0.32%—HCL HiveAI24/8/202628/8/2026
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
AplazadaMedia (5.3)0.15%—HCL Hive Keycloak IAMAI24/8/202629/9/2026
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
AplazadaMedia (4.8)0.24%—HCL Intelliops Event ManagementAI20/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
AplazadaMedia (5)0.28%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
Orbitaley — Vulnerabilidades