Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.30%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch29/6/20262/7/2026
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
AnalizadaAlta (7.8)0.27%—Hcltech Traveler FOR Microsoft Outlook27/6/20266/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party…
AnalizadaMedia (5.5)0.15%—Hcltech Traveler FOR Microsoft Outlook27/6/202629/9/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
AnalizadaAlta (7.8)0.09%—Hcltech Traveler FOR Microsoft Outlook26/6/20261/10/2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Pendiente de análisisBaja (3.5)0.16%—HCL ConnectionsAI23/6/20266/10/2026
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
AplazadaMedia (6.3)0.16%—HCL VerseAICompose-rich-editorAI19/6/202622/6/2026
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
AnalizadaMedia (5.3)0.20%—Hcltech Icontrol17/6/20266/10/2026
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
AnalizadaCrítica (9.8)0.45%—Hcltech ZIE FOR WEB17/6/20266/10/2026
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to…
AnalizadaMedia (6.1)0.25%—Hcltech Devops Plan11/6/202627/7/2026
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
AnalizadaAlta (8.7)0.92%—Hcltech Digital ExperienceHcltech Digital Experience Compose5/6/202623/7/2026
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
AnalizadaMedia (6.1)0.14%—Hcltech Digital Experience ComposeHcltech Digital Experience5/6/202623/7/2026
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
AnalizadaMedia (6.1)0.15%—Hcltech Digital Experience ComposeHcltech Digital Experience5/6/202623/7/2026
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
Pendiente de análisisBaja (3.3)0.10%—HCL Bigfix Cloud Lifecycle ManagementAI4/6/202622/7/2026
HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure.
Pendiente de análisisAlta (8.1)0.27%—HCL Hive Telco ObservabilityAIKeycloakAI4/6/202622/7/2026
HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
AnalizadaAlta (8.8)0.20%—Hcltech Icontrol4/6/202622/7/2026
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
AnalizadaMedia (4.3)0.16%—Hcltech Icontrol4/6/202622/7/2026
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems…
AnalizadaMedia (5.3)0.16%—Hcltech Icontrol4/6/202622/7/2026
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
AnalizadaMedia (4.3)0.10%—Hcltech Icontrol4/6/202622/7/2026
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
AnalizadaMedia (4.3)0.17%—Hcltech Icontrol4/6/202622/7/2026
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Pendiente de análisisBaja (3.1)0.15%—HCL IreflectionAI2/6/202622/7/2026
HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
Pendiente de análisisMedia (4)0.15%—HCL Bigfix Remote Control ServerAI27/5/202617/6/2026
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
Pendiente de análisisMedia (6.5)0.26%—HCL DominoiqAI20/5/202623/7/2026
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query. This could enable an authenticated attacker to view sensitive data.
AnalizadaMedia (6.5)0.16%—Hcltech Bigfix Service Management20/5/202624/7/2026
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.
AnalizadaCrítica (9.8)0.18%—Hcltech Bigfix Service Management20/5/202624/7/2026
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
AplazadaMedia (4.6)0.12%—HCL ConnectionsAI18/5/202617/6/2026
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.