Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.5) | — | — | HCL Bigfix Service ManagementAI | 6/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior. | |
| Analizada | Baja (3.7) | 0.21% | — | Hcltech Bigfix Service Management | 1/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks. | |
| En análisis | Media (4.3) | 0.16% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. | |
| Analizada | Alta (7.4) | 0.15% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation. | |
| Analizada | Baja (2.2) | 0.06% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting… | |
| Analizada | Alta (7.2) | 0.20% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data. | |
| En análisis | Baja (3.1) | 0.15% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation… | |
| En análisis | Baja (3.1) | 0.25% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets. | |
| En análisis | Baja (3.1) | 0.24% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of… | |
| En análisis | Media (6.5) | 0.45% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access. | |
| En análisis | Media (6.4) | 0.29% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise. | |
| En análisis | Media (5) | 0.16% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries. | |
| En análisis | Alta (7.6) | 0.28% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users. | |
| En análisis | Alta (8.1) | 0.35% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. | |
| En análisis | Crítica (9.3) | 0.34% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 21/9/2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | |
| En análisis | Crítica (9.8) | 0.47% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile… | |
| Analizada | Media (6.5) | 0.16% | — | Hcltech Bigfix Service Management | 20/5/2026 | 24/7/2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. | |
| Analizada | Crítica (9.8) | 0.18% | — | Hcltech Bigfix Service Management | 20/5/2026 | 24/7/2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. | |
| Analizada | Alta (8.3) | 0.25% | — | Hcltech Bigfix Service Management | 6/5/2026 | 17/6/2026 | HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in exposure of sensitive data or unauthorized system modifications | |
| Analizada | Alta (7.2) | 0.18% | — | Hcltech Bigfix Service Management | 6/5/2026 | 30/9/2026 | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized changes. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 6/5/2026 | 30/9/2026 | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception. | |
| Analizada | Alta (8.8) | 0.23% | — | Hcltech Bigfix Service Management | 6/5/2026 | 30/9/2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access. |