Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.41% | — | Hcltech Connections | 7/12/2023 | 17/6/2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication… | |
| Modificada | Media (6.1) | 0.42% | — | Hcltech Connections | 9/11/2023 | 17/6/2026 | HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based… | |
| Modificada | Media (4.3) | 0.51% | — | Hcltech Commerce | 23/10/2023 | 17/6/2026 | HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system. | |
| Modificada | Crítica (9.8) | 0.45% | — | Hcltech HCL Compass | 19/10/2023 | 17/6/2026 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts. | |
| Modificada | Media (6.5) | 0.29% | — | Hcltech HCL Compass | 19/10/2023 | 17/6/2026 | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. | |
| Modificada | Alta (8.8) | 0.48% | — | Hcltech HCL Compass | 18/10/2023 | 17/6/2026 | HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser. | |
| Modificada | Alta (7.8) | 0.17% | — | Hcltech Appscan Presence | 17/10/2023 | 17/6/2026 | An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges. | |
| Modificada | Media (6.1) | 0.36% | — | Hcltech Digital Experience | 11/10/2023 | 17/6/2026 | HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | |
| Modificada | Alta (8.8) | 1.4% | — | Apache Xerces-c++Hcltech Bigfix PlatformFedoraproject Fedora | 11/10/2023 | 17/6/2026 | An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | |
| Modificada | Media (5.3) | 0.34% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | |
| Modificada | Alta (8.2) | 0.33% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | |
| Modificada | Media (4.4) | 0.15% | — | Hcltech Bigfix Patch Management | 11/10/2023 | 17/6/2026 | Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user. | |
| Modificada | Media (5.3) | 0.39% | — | Hcltech Domino | 8/9/2023 | 17/6/2026 | In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. | |
| Modificada | Media (5.5) | 0.18% | — | Hcltech Traveler TO DO | 11/8/2023 | 17/6/2026 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | |
| Modificada | Media (5.5) | 0.18% | — | Hcltech Traveler Companion | 11/8/2023 | 17/6/2026 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | |
| Modificada | Media (4.3) | 0.41% | — | Hcltech Traveler TO DO | 11/8/2023 | 17/6/2026 | If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved. | |
| Modificada | Alta (7.1) | 0.18% | — | Hcltech HCL Nomad | 10/8/2023 | 17/6/2026 | If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. | |
| Modificada | Alta (7.1) | 0.11% | — | Hcltech Dryice Iautomate | 9/8/2023 | 17/6/2026 | HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | |
| Modificada | Alta (7.1) | 0.10% | — | Hcltech Dryice Mycloud | 9/8/2023 | 17/6/2026 | HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | |
| Modificada | Media (6.1) | 0.38% | — | Hcltech Unica | 3/8/2023 | 17/6/2026 | A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's session and perform other attacks. | |
| Modificada | Media (6.1) | 0.38% | — | Hcltech Unica | 3/8/2023 | 17/6/2026 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could hijack a user's session and perform other attacks. | |
| Modificada | Media (6.1) | 0.38% | — | Hcltech Unica | 3/8/2023 | 17/6/2026 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker could hijack a user's session and perform other attacks. | |
| Modificada | Alta (8.8) | 0.57% | — | Hcltech Unica | 3/8/2023 | 17/6/2026 | A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges. | |
| Modificada | Alta (8.8) | 0.53% | — | Hcltech Unica | 3/8/2023 | 17/6/2026 | The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service. | |
| Modificada | Media (5.4) | 0.39% | — | Hcltech Verse | 1/8/2023 | 17/6/2026 | HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. |