Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.69%—Hcltech Domino19/12/202217/6/2026
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This…
ModificadaAlta (7.8)0.69%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.
ModificadaAlta (7.8)0.69%—Hcltech Domino19/12/202217/6/2026
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.
ModificadaAlta (7.8)0.69%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This…
ModificadaAlta (7.8)0.69%—Hcltech Domino19/12/202217/6/2026
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754. This…
ModificadaMedia (6.5)0.27%—Hcltech Bigfix Platform19/12/202217/6/2026
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
ModificadaMedia (6.1)0.37%—Hcltech HCL Digital Experience19/12/202217/6/2026
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
ModificadaAlta (7.8)0.13%—Hcltech Bigfix Platform19/12/202217/6/2026
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
ModificadaMedia (5.4)0.30%—Hcltech Digital Experience19/12/202217/6/2026
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
ModificadaMedia (6.5)0.40%—Hcltech Sametime12/12/202217/6/2026
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.
ModificadaMedia (4.9)0.58%—Hcltechsw HCL Launch12/12/202217/6/2026
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
ModificadaAlta (7.1)0.18%—Hcltechsw HCL Workload Automation12/12/202217/6/2026
HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.
ModificadaCrítica (9.8)0.73%—Hcltechsw HCL Commerce12/12/202217/6/2026
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
ModificadaMedia (5.5)0.19%—Hcltech Domino4/11/202217/6/2026
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
ModificadaAlta (8.8)0.30%—Hcltech Domino4/11/202217/6/2026
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
ModificadaAlta (7.5)0.31%—Hcltech Verse1/11/202217/6/2026
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
ModificadaAlta (7.5)0.21%—Hcltech HCL Launch Container Image31/10/202217/6/2026
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
ModificadaMedia (5.4)0.41%—Hcltech HCL Digital Experience22/9/202217/6/2026
User input included in error response, which could be used in a phishing attack.
ModificadaMedia (5.3)0.88%—Evohclaimable Project Evohclaimable21/9/202217/6/2026
Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48ae allows remote attackers to execute fraudulent NFT transfers.
ModificadaMedia (4.8)0.45%—Hcltech Traveler15/9/202217/6/2026
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
ModificadaAlta (7.5)0.78%—Hcltech Versionvault Express30/8/202217/6/2026
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
ModificadaMedia (6.5)0.46%—Hcltech Versionvault Express30/8/202217/6/2026
HCL VersionVault Express exposes administrator credentials.
ModificadaAlta (7.5)0.57%—Hcltech DominoHcltech HCL Inotes29/8/202217/6/2026
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
ModificadaAlta (7.4)0.53%—Hcltech HCL InotesHcltech Domino29/8/202217/6/2026
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
ModificadaMedia (6.1)0.64%—Hcltech HCL InotesHcltech Domino29/8/202217/6/2026
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security…
Orbitaley — Vulnerabilidades