Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.30% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | |
| Aplazada | Media (5.3) | 0.40% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use… | |
| Aplazada | Media (4.3) | 0.31% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy… | |
| Aplazada | Media (6.5) | 0.27% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration | |
| Aplazada | Media (5.3) | 0.40% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other… | |
| Aplazada | Crítica (9.1) | 0.29% | — | HCL Aftermarket EPCAI | 17/7/2026 | 1/10/2026 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the… | |
| Aplazada | Media (6.5) | 0.16% | — | HCL Traveler FOR Microsoft OutlookAI | 17/7/2026 | 17/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Media (5.3) | 0.40% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map… | |
| Analizada | Alta (7.5) | 0.46% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To… | |
| Analizada | Alta (7.5) | 0.22% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and… | |
| Analizada | Crítica (9.8) | 0.35% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain… | |
| Analizada | Baja (3.1) | 0.27% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and… | |
| Analizada | Media (6.5) | 0.16% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF… | |
| Analizada | Alta (8.2) | 0.32% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further… | |
| Analizada | Media (5.3) | 0.33% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every… | |
| Analizada | Alta (7.2) | 0.28% | — | Hcltech Dfxanalytics | 16/7/2026 | 17/7/2026 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session… | |
| Analizada | Alta (8.2) | 0.42% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without… | |
| Analizada | Media (6.3) | 0.30% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or… | |
| Analizada | Alta (8.2) | 0.43% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. | |
| Analizada | Media (6.3) | 0.19% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application. | |
| Pendiente de análisis | Media (5.5) | 0.44% | — | HCL NotesAI | 15/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | HCL Bigfix PlatformAI | 14/7/2026 | 15/7/2026 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service. | |
| Analizada | Media (6.5) | 0.38% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 9/7/2026 | 13/7/2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | |
| Analizada | Media (5.5) | 0.15% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 9/7/2026 | 10/7/2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.5) | 0.26% | — | Hcltechsw HCL Devops Deploy | 9/7/2026 | 10/7/2026 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. |