Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.25% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution. | |
| Analizada | Media (6.1) | 0.17% | — | Hcltech Dfxanalytics | 6/5/2026 | 7/10/2026 | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should instead be managed by a robust Content Security… | |
| Analizada | Media (5.3) | 0.16% | — | Hcltech Dfxanalytics | 6/5/2026 | 7/10/2026 | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations. | |
| Analizada | Crítica (9.1) | 0.08% | — | Hcltech Dfxanalytics | 6/5/2026 | 7/10/2026 | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information. | |
| Analizada | Crítica (9.8) | 0.17% | — | Hcltech Dfxanalytics | 6/5/2026 | 7/10/2026 | HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to gain unauthorized access or compromise the application. | |
| Analizada | Media (6.1) | 0.19% | — | Hcltech Dfxanalytics | 6/5/2026 | 7/10/2026 | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS) | |
| Analizada | Media (5.3) | 0.09% | — | Hcltech Bigfix Service Management | 21/4/2026 | 7/10/2026 | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data. | |
| Analizada | Alta (8.2) | 0.19% | — | Hcltech Bigfix Service Management | 21/4/2026 | 7/10/2026 | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing… | |
| Analizada | Media (5.3) | 0.09% | — | Hcltech Aion | 15/4/2026 | 7/10/2026 | HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure. | |
| Analizada | Crítica (9.8) | 0.19% | — | Hcltech Devops Velocity | 13/4/2026 | 7/10/2026 | Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7. | |
| Analizada | Baja (3.3) | 0.11% | — | Hcltech Bigfix Platform | 2/4/2026 | 17/6/2026 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | |
| Analizada | Alta (7.8) | 0.10% | — | Hcltech Bigfix Platform | 2/4/2026 | 17/6/2026 | HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions. | |
| Analizada | Media (5.5) | 0.12% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | |
| Analizada | Alta (7.5) | 0.19% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets. | |
| Analizada | Alta (7.5) | 0.27% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database. | |
| Analizada | Crítica (9.8) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data. | |
| Analizada | Media (6.5) | 0.18% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application. | |
| Analizada | Media (5.3) | 0.20% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout. | |
| Analizada | Alta (8.1) | 0.22% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user. | |
| Analizada | Media (4.3) | 0.18% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive… | |
| Analizada | Media (4.3) | 0.23% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks. | |
| Analizada | Alta (8.8) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response.. | |
| Analizada | Crítica (9.8) | 1.00% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc. | |
| Analizada | Crítica (9.8) | 0.24% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. |