Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.30% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 29/6/2026 | 2/7/2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. | |
| Analizada | Alta (7.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 6/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party… | |
| Analizada | Media (5.5) | 0.15% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 29/9/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application. | |
| Analizada | Alta (7.8) | 0.09% | — | Hcltech Traveler FOR Microsoft Outlook | 26/6/2026 | 1/10/2026 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | |
| Pendiente de análisis | Baja (3.5) | 0.16% | — | HCL ConnectionsAI | 23/6/2026 | 6/10/2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario. | |
| Aplazada | Media (6.3) | 0.16% | — | HCL VerseAICompose-rich-editorAI | 19/6/2026 | 22/6/2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations. | |
| Analizada | Media (5.3) | 0.20% | — | Hcltech Icontrol | 17/6/2026 | 6/10/2026 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity | |
| Analizada | Crítica (9.8) | 0.45% | — | Hcltech ZIE FOR WEB | 17/6/2026 | 6/10/2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to… | |
| Analizada | Media (6.1) | 0.25% | — | Hcltech Devops Plan | 11/6/2026 | 27/7/2026 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking | |
| Analizada | Alta (8.7) | 0.92% | — | Hcltech Digital ExperienceHcltech Digital Experience Compose | 5/6/2026 | 23/7/2026 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. | |
| Analizada | Media (6.1) | 0.14% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | |
| Analizada | Media (6.1) | 0.15% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser. | |
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL Bigfix Cloud Lifecycle ManagementAI | 4/6/2026 | 22/7/2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure. | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Analizada | Alta (8.8) | 0.20% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | |
| Analizada | Media (4.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems… | |
| Analizada | Media (5.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. | |
| Analizada | Media (4.3) | 0.10% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. | |
| Analizada | Media (4.3) | 0.17% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. | |
| Pendiente de análisis | Baja (3.1) | 0.15% | — | HCL IreflectionAI | 2/6/2026 | 22/7/2026 | HCL iReflection Third party vulnerable and outdated components issue was detected in the web application | |
| Pendiente de análisis | Media (4) | 0.15% | — | HCL Bigfix Remote Control ServerAI | 27/5/2026 | 17/6/2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. | |
| Pendiente de análisis | Media (6.5) | 0.26% | — | HCL DominoiqAI | 20/5/2026 | 23/7/2026 | The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query. This could enable an authenticated attacker to view sensitive data. | |
| Analizada | Media (6.5) | 0.16% | — | Hcltech Bigfix Service Management | 20/5/2026 | 24/7/2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. | |
| Analizada | Crítica (9.8) | 0.18% | — | Hcltech Bigfix Service Management | 20/5/2026 | 24/7/2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. | |
| Aplazada | Media (4.6) | 0.12% | — | HCL ConnectionsAI | 18/5/2026 | 17/6/2026 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. |