Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.24%—Hcltech Bigfix Mobile27/7/202317/6/2026
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
ModificadaAlta (8.8)0.89%—Hcltech Bigfix Mobile27/7/202317/6/2026
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
ModificadaMedia (6.1)0.34%—Hcltech Verse26/7/202317/6/2026
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive…
ModificadaMedia (6.5)0.16%—Hcltech Bigfix Webui18/7/202317/6/2026
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).
ModificadaAlta (7.5)0.30%—Hcltech Bigfix Webui18/7/202317/6/2026
The BigFix WebUI uses weak cipher suites.
ModificadaMedia (6.1)0.36%—Hcltech Bigfix Webui18/7/202317/6/2026
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
ModificadaAlta (8.8)0.45%—Hcltech Bigfix Webui18/7/202317/6/2026
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
ModificadaMedia (5.5)0.15%—Hcltechsw HCL Launch10/7/202317/6/2026
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
ModificadaMedia (6.5)0.42%—Hcltech Bigfix Webui Insights23/6/202317/6/2026
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
ModificadaMedia (6.1)0.30%—Hcltech Bigfix OSD Bare Metal Server22/6/202317/6/2026
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.
ModificadaAlta (7.8)0.11%—Hcltech Bigfix OSD Bare Metal Server22/6/202317/6/2026
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
ModificadaMedia (6.1)0.32%—Hcltech Bigfix OSD Bare Metal Server22/6/202317/6/2026
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
ModificadaMedia (5.3)0.45%—HCL Domino Appdev Pack23/5/202317/6/2026
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users.
ModificadaAlta (8.1)0.76%—Hcltech Workload Automation26/4/202317/6/2026
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaAlta (8.1)0.82%—Hcltech Workload Automation26/4/202317/6/2026
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaMedia (5.4)0.34%—Hcltechsw HCL Launch2/4/202317/6/2026
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
ModificadaAlta (8.8)0.35%—Hcltech HCL Compass2/4/202317/6/2026
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
ModificadaMedia (6.1)0.57%—Hcltech Verse10/3/202317/6/2026
HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
ModificadaMedia (5.4)0.29%—Hcltech HCL Leap12/2/202317/6/2026
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
ModificadaAlta (7.5)0.35%—Hcltech Bigfix Mobile20/1/202317/6/2026
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.
ModificadaAlta (7.5)0.32%—Hcltech Bigfix Server Automation24/12/202217/6/2026
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
ModificadaMedia (6.5)0.41%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access.
ModificadaMedia (5.3)0.22%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access.
ModificadaMedia (5.8)0.39%—Hcltech Bigfix Webui21/12/202217/6/2026
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
ModificadaAlta (7.8)0.75%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This…
Orbitaley — Vulnerabilidades