Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.23% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. | |
| Aplazada | Media (6.6) | 0.26% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. | |
| Aplazada | Media (5.4) | 0.25% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | |
| Aplazada | Media (4.3) | 0.29% | — | HCL AionAI | 13/8/2026 | 28/8/2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | |
| Aplazada | Baja (3.7) | 0.12% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | |
| Aplazada | Baja (3.4) | 0.21% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | |
| Aplazada | Media (5.6) | 0.15% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. | |
| Aplazada | Media (4.7) | 0.11% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | HCL Bigfix MobileAI | 10/8/2026 | 28/8/2026 | HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | HCL Bigfix MobileAI | 10/8/2026 | 28/8/2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | |
| Aplazada | Media (5.4) | 0.29% | — | HCL Digital ExperienceAIHCL Digital Experience ComposeAI | 5/8/2026 | 28/8/2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HCL Appscan PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Analizada | Media (6.5) | 0.15% | — | Hcltech Icontrol | 3/8/2026 | 5/8/2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. | |
| Analizada | Media (5.3) | 0.27% | — | Hcltech Icontrol | 3/8/2026 | 5/8/2026 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated. | |
| Analizada | Media (5.3) | 0.30% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. | |
| Analizada | Baja (3.3) | 0.14% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |
| Analizada | Media (5.3) | 0.33% | — | Hcltech Icontrol | 31/7/2026 | 6/8/2026 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status | |
| Analizada | Baja (3.3) | 0.14% | — | Hcltech Icontrol | 31/7/2026 | 6/8/2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |
| Aplazada | Media (4.3) | 0.31% | — | HCL IcontrolAI | 31/7/2026 | 29/9/2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type. | |
| Analizada | Baja (3.5) | 0.27% | — | Hcltech Connections | 27/7/2026 | 20/8/2026 | An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. | |
| Analizada | Baja (3.5) | 0.27% | — | Hcltech Connections | 27/7/2026 | 20/8/2026 | HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data. | |
| Analizada | Baja (3.1) | 0.22% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse. | |
| Analizada | Baja (3.1) | 0.15% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. | |
| Analizada | Baja (2.6) | 0.15% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens. |