Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Domino | 19/12/2022 | 17/6/2026 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This… | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Domino | 19/12/2022 | 17/6/2026 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This… | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Domino | 19/12/2022 | 17/6/2026 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754. This… | |
| Modificada | Media (6.5) | 0.27% | — | Hcltech Bigfix Platform | 19/12/2022 | 17/6/2026 | There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script. | |
| Modificada | Media (6.1) | 0.37% | — | Hcltech HCL Digital Experience | 19/12/2022 | 17/6/2026 | In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. | |
| Modificada | Alta (7.8) | 0.13% | — | Hcltech Bigfix Platform | 19/12/2022 | 17/6/2026 | In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent. | |
| Modificada | Media (5.4) | 0.30% | — | Hcltech Digital Experience | 19/12/2022 | 17/6/2026 | In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded. | |
| Modificada | Media (6.5) | 0.40% | — | Hcltech Sametime | 12/12/2022 | 17/6/2026 | Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users. | |
| Modificada | Media (4.9) | 0.58% | — | Hcltechsw HCL Launch | 12/12/2022 | 17/6/2026 | HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches. | |
| Modificada | Alta (7.1) | 0.18% | — | Hcltechsw HCL Workload Automation | 12/12/2022 | 17/6/2026 | HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash. | |
| Modificada | Crítica (9.8) | 0.73% | — | Hcltechsw HCL Commerce | 12/12/2022 | 17/6/2026 | HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes. | |
| Modificada | Media (5.5) | 0.19% | — | Hcltech Domino | 4/11/2022 | 17/6/2026 | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record. | |
| Modificada | Alta (8.8) | 0.30% | — | Hcltech Domino | 4/11/2022 | 17/6/2026 | HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user. | |
| Modificada | Alta (7.5) | 0.31% | — | Hcltech Verse | 1/11/2022 | 17/6/2026 | The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | |
| Modificada | Alta (7.5) | 0.21% | — | Hcltech HCL Launch Container Image | 31/10/2022 | 17/6/2026 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages. | |
| Modificada | Media (5.4) | 0.41% | — | Hcltech HCL Digital Experience | 22/9/2022 | 17/6/2026 | User input included in error response, which could be used in a phishing attack. | |
| Modificada | Media (5.3) | 0.88% | — | Evohclaimable Project Evohclaimable | 21/9/2022 | 17/6/2026 | Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48ae allows remote attackers to execute fraudulent NFT transfers. | |
| Modificada | Media (4.8) | 0.45% | — | Hcltech Traveler | 15/9/2022 | 17/6/2026 | There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf). | |
| Modificada | Alta (7.5) | 0.78% | — | Hcltech Versionvault Express | 30/8/2022 | 17/6/2026 | An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service. | |
| Modificada | Media (6.5) | 0.46% | — | Hcltech Versionvault Express | 30/8/2022 | 17/6/2026 | HCL VersionVault Express exposes administrator credentials. | |
| Modificada | Alta (7.5) | 0.57% | — | Hcltech DominoHcltech HCL Inotes | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | |
| Modificada | Alta (7.4) | 0.53% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | |
| Modificada | Media (6.1) | 0.64% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security… |