Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.2) | 0.28% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system. | |
| Analizada | Baja (3.1) | 0.25% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security. | |
| Analizada | Baja (2.2) | 0.26% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions. | |
| Analizada | Media (6.5) | 0.28% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | |
| Analizada | Media (4.2) | 0.20% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | |
| Analizada | Media (4.3) | 0.25% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | |
| Analizada | Baja (3.7) | 0.24% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. | |
| Analizada | Media (6.9) | 0.42% | — | Hcltech Devops Plan | 21/7/2026 | 26/9/2026 | HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | |
| Analizada | Baja (2.3) | 0.22% | — | Hcltech Devops Plan | 21/7/2026 | 26/9/2026 | HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | HCL CommerceAI | 20/7/2026 | 21/7/2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. | |
| Analizada | Media (4.3) | 0.22% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting. | |
| Analizada | Media (5.4) | 0.20% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. | |
| Analizada | Media (4.6) | 0.21% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | |
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL DfmproAIHCL DfxanalyticsAIHCL DfxserverAI | 17/7/2026 | 29/9/2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary. | |
| Aplazada | Media (5.3) | 0.33% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts. | |
| Aplazada | Media (4.2) | 0.20% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard). | |
| Aplazada | Media (4.3) | 0.30% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server… | |
| Aplazada | Media (5.3) | 0.33% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack. | |
| Aplazada | Media (5.3) | 0.33% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system | |
| Aplazada | Baja (3.7) | 0.24% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. | |
| Aplazada | Media (4.2) | 0.13% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function. | |
| Aplazada | Media (4.3) | 0.30% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have… | |
| Aplazada | Media (4.3) | 0.28% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive… |