Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.24% | — | Hcltech Bigfix Mobile | 27/7/2023 | 17/6/2026 | HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application. | |
| Modificada | Alta (8.8) | 0.89% | — | Hcltech Bigfix Mobile | 27/7/2023 | 17/6/2026 | HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server. | |
| Modificada | Media (6.1) | 0.34% | — | Hcltech Verse | 26/7/2023 | 17/6/2026 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive… | |
| Modificada | Media (6.5) | 0.16% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). | |
| Modificada | Alta (7.5) | 0.30% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | The BigFix WebUI uses weak cipher suites. | |
| Modificada | Media (6.1) | 0.36% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | |
| Modificada | Alta (8.8) | 0.45% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | |
| Modificada | Media (5.5) | 0.15% | — | Hcltechsw HCL Launch | 10/7/2023 | 17/6/2026 | HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. | |
| Modificada | Media (6.5) | 0.42% | — | Hcltech Bigfix Webui Insights | 23/6/2023 | 17/6/2026 | A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | |
| Modificada | Media (6.1) | 0.30% | — | Hcltech Bigfix OSD Bare Metal Server | 22/6/2023 | 17/6/2026 | Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain. | |
| Modificada | Alta (7.8) | 0.11% | — | Hcltech Bigfix OSD Bare Metal Server | 22/6/2023 | 17/6/2026 | The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure. | |
| Modificada | Media (6.1) | 0.32% | — | Hcltech Bigfix OSD Bare Metal Server | 22/6/2023 | 17/6/2026 | A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain. | |
| Modificada | Media (5.3) | 0.45% | — | HCL Domino Appdev Pack | 23/5/2023 | 17/6/2026 | The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users. | |
| Modificada | Alta (8.1) | 0.76% | — | Hcltech Workload Automation | 26/4/2023 | 17/6/2026 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Modificada | Alta (8.1) | 0.82% | — | Hcltech Workload Automation | 26/4/2023 | 17/6/2026 | HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Modificada | Media (5.4) | 0.34% | — | Hcltechsw HCL Launch | 2/4/2023 | 17/6/2026 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. | |
| Modificada | Alta (8.8) | 0.35% | — | Hcltech HCL Compass | 2/4/2023 | 17/6/2026 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. | |
| Modificada | Media (6.1) | 0.57% | — | Hcltech Verse | 10/3/2023 | 17/6/2026 | HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. | |
| Modificada | Media (5.4) | 0.29% | — | Hcltech HCL Leap | 12/2/2023 | 17/6/2026 | An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page. | |
| Modificada | Alta (7.5) | 0.35% | — | Hcltech Bigfix Mobile | 20/1/2023 | 17/6/2026 | HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts. | |
| Modificada | Alta (7.5) | 0.32% | — | Hcltech Bigfix Server Automation | 24/12/2022 | 17/6/2026 | BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed. | |
| Modificada | Media (6.5) | 0.41% | — | Hcltechsw Bigfix Insights FOR Vulnerability Remediation | 21/12/2022 | 17/6/2026 | Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. | |
| Modificada | Media (5.3) | 0.22% | — | Hcltechsw Bigfix Insights FOR Vulnerability Remediation | 21/12/2022 | 17/6/2026 | Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access. | |
| Modificada | Media (5.8) | 0.39% | — | Hcltech Bigfix Webui | 21/12/2022 | 17/6/2026 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | |
| Modificada | Alta (7.8) | 0.75% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This… |