Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.6) | 0.11% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions. | |
| Aplazada | Baja (2.3) | 0.11% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under specific conditions. | |
| Aplazada | Media (5.4) | 0.18% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions. | |
| Aplazada | Baja (3) | 0.14% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices. | |
| Aplazada | Media (4.3) | 0.08% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions | |
| Aplazada | Media (5.4) | 0.05% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions. | |
| Aplazada | Baja (2.6) | 0.11% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions. | |
| Aplazada | Media (5.1) | 0.11% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under certain conditions | |
| Aplazada | Media (5.1) | 0.11% | — | HCL AionAI | 14/5/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions. | |
| Pendiente de análisis | Alta (8.3) | 0.21% | — | HCL Bigfix SCM ReportingAIJqueryAI | 13/5/2026 | 17/6/2026 | The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Analizada | Alta (8.3) | 0.25% | — | Hcltech Bigfix Service Management | 6/5/2026 | 17/6/2026 | HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in exposure of sensitive data or unauthorized system modifications | |
| Analizada | Alta (7.2) | 0.15% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized changes. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception. | |
| Analizada | Alta (8.8) | 0.14% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access. | |
| Analizada | Media (5.4) | 0.13% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. | |
| Analizada | Media (4.6) | 0.13% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information. | |
| Analizada | Media (6.5) | 0.13% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality. | |
| Analizada | Media (4.3) | 0.13% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically… | |
| Analizada | Alta (7.5) | 0.16% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. . | |
| Analizada | Media (5.3) | 0.13% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities. | |
| Analizada | Baja (3.5) | 0.14% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. . | |
| Analizada | Media (5.7) | 0.09% | — | Hcltech Bigfix Service Management | 6/5/2026 | 7/10/2026 | HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data. | |
| Pendiente de análisis | Baja (2.7) | 0.22% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the risk of misconfiguration and operational errors. |