Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Aplazada | Media (6.1) | 0.19% | — | IBM Bigfix WebuiAI | 10/10/2025 | 17/6/2026 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks. | |
| Modificada | Media (6.5) | 0.16% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). | |
| Modificada | Alta (7.5) | 0.30% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | The BigFix WebUI uses weak cipher suites. | |
| Modificada | Media (6.1) | 0.36% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | |
| Modificada | Alta (8.8) | 0.45% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | |
| Modificada | Media (6.5) | 0.42% | — | Hcltech Bigfix Webui Insights | 23/6/2023 | 17/6/2026 | A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | |
| Modificada | Media (5.8) | 0.39% | — | Hcltech Bigfix Webui | 21/12/2022 | 17/6/2026 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | |
| Modificada | Media (6.5) | 0.55% | — | Hcltech Bigfix Webui | 6/5/2022 | 17/6/2026 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Bigfix Webui | 17/7/2020 | 17/6/2026 | HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in… | |
| Modificada | Crítica (9.8) | 2.1% | — | IBM Bigfix Webui Profile ManagementIBM Bigfix Webui Software Distribution | 15/4/2019 | 17/6/2026 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886. |