Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.26% | — | HCL DominoiqAI | 20/5/2026 | 23/7/2026 | The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query. This could enable an authenticated attacker to view sensitive data. | |
| Pendiente de análisis | Baja (3.7) | 0.24% | — | HCL Nomad ServerAIHCL DominoAI | 11/3/2026 | 17/6/2026 | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors. | |
| Aplazada | Media (5.3) | 0.24% | — | DominokitAI | 4/11/2025 | 17/6/2026 | The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Analizada | Baja (2.7) | 0.21% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem. | |
| Analizada | Media (6.1) | 0.26% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications. | |
| Analizada | Media (5.4) | 0.25% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | |
| Analizada | Media (5.3) | 0.31% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Insufficient default configuration in HCL Leap allows anonymous access to directory information. | |
| Analizada | Media (6.1) | 0.24% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters. | |
| Analizada | Alta (7.5) | 0.23% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. | |
| Analizada | Media (5.4) | 0.23% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. | |
| Analizada | Media (5.4) | 0.29% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications | |
| Analizada | Media (5.4) | 0.29% | — | Hcltech Domino Leap | 30/4/2025 | 17/6/2026 | Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. | |
| Analizada | Alta (7.5) | 0.31% | — | Hcltech Nomad Server ON Domino | 1/10/2024 | 17/6/2026 | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (6.5) | 0.40% | — | Hcltech Nomad Server ON Domino | 25/9/2024 | 17/6/2026 | HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information. | |
| Analizada | Alta (7.5) | 0.29% | — | Hcltech Nomad Server ON Domino | 19/7/2024 | 17/6/2026 | HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information. | |
| Modificada | Alta (7.5) | 0.47% | — | Hcltech Domino | 8/7/2024 | 17/6/2026 | A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system. | |
| Modificada | Media (6.5) | 0.34% | — | Hcltech Nomad Server ON Domino | 5/7/2024 | 17/6/2026 | HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability. | |
| Aplazada | Alta (8.4) | 0.42% | — | CA Sitemanager WEB Agent FOR IISAICA Sitemanager WEB Agent FOR DominoAI | 14/6/2024 | 17/6/2026 | A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser. | |
| Modificada | Media (5.4) | 0.31% | — | Hcltech Domino | 6/6/2024 | 17/6/2026 | The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it. | |
| Analizada | Media (5.9) | 0.47% | — | Hcltech Domino | 29/2/2024 | 17/6/2026 | Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password,… | |
| Modificada | Media (5.3) | 0.39% | — | Hcltech Domino | 8/9/2023 | 17/6/2026 | In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. | |
| Modificada | Media (5.3) | 0.45% | — | HCL Domino Appdev Pack | 23/5/2023 | 17/6/2026 | The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users. | |
| Modificada | Alta (8) | 0.70% | — | Domino Project Domino | 11/1/2023 | 17/6/2026 | A vulnerability was found in dobos domino. It has been rated as critical. Affected by this issue is some unknown functionality in the library src/Complex.Domino.Lib/Lib/EntityFactory.cs. The manipulation leads to sql injection. Upgrading to version 0.1.5524.38553 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Domino | 19/12/2022 | 17/6/2026 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This… | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Domino | 19/12/2022 | 17/6/2026 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. |