Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.27% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | |
| Analizada | Crítica (9.8) | 0.29% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | |
| Analizada | Media (6.5) | 0.25% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user. | |
| Analizada | Alta (7.5) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks. | |
| Pendiente de análisis | Media (6.3) | 0.15% | — | HCL TravelerAI | 24/3/2026 | 17/6/2026 | HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks. | |
| Analizada | Media (4.3) | 0.28% | — | Hcltech Traveler | 24/3/2026 | 17/6/2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain… | |
| Analizada | Media (5.4) | 0.16% | — | Hcltech Connections | 19/3/2026 | 17/6/2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based authentication credentials and comprise user's… | |
| Modificada | Media (5.4) | 0.17% | — | Hcltech Unica | 19/3/2026 | 17/6/2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe… | |
| Analizada | Media (6.1) | 0.16% | — | Hcltech UnicaHcltech Unica Audience CentralHcltech Unica CampaignHcltech Unica Centralised Offer Management+5 | 17/3/2026 | 17/6/2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in… | |
| Analizada | Baja (2.7) | 0.19% | — | Hcltech Sametime | 17/3/2026 | 17/6/2026 | HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server. | |
| Analizada | Crítica (9.8) | 0.28% | — | Hcltech UnicaHcltech Unica Audience Central | 16/3/2026 | 17/6/2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition… | |
| Analizada | Media (5.3) | 0.13% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions. | |
| Analizada | Media (5.3) | 0.15% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions. | |
| Analizada | Media (5.3) | 0.08% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour. | |
| Analizada | Alta (8.2) | 0.14% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes. | |
| Analizada | Alta (7.8) | 0.10% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files. | |
| Analizada | Media (6.5) | 0.11% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure. | |
| Analizada | Alta (7.5) | 0.14% | — | Hcltech Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios. | |
| Analizada | Crítica (9.8) | 0.12% | — | HCL Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system | |
| Analizada | Alta (7.2) | 0.13% | — | HCL Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning container configurations with security best… | |
| Analizada | Alta (7.3) | 0.22% | — | HCL Aion | 16/3/2026 | 17/6/2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions. | |
| Pendiente de análisis | Baja (3.7) | 0.24% | — | HCL Nomad ServerAIHCL DominoAI | 11/3/2026 | 17/6/2026 | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (3.3) | 0.13% | — | Hcltech Sametime | 10/3/2026 | 17/6/2026 | HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL | |
| Analizada | Baja (3.3) | 0.10% | — | Hcltech Sametime | 5/3/2026 | 17/6/2026 | HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs. | |
| Analizada | Baja (3.3) | 0.11% | — | Hcltech Devops Plan | 3/3/2026 | 27/7/2026 | IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. |