Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.26%—HCL DominoiqAI20/5/202623/7/2026
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query. This could enable an authenticated attacker to view sensitive data.
Pendiente de análisisBaja (3.7)0.24%—HCL Nomad ServerAIHCL DominoAI11/3/202617/6/2026
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.
AplazadaMedia (5.3)0.24%—DominokitAI4/11/202517/6/2026
The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.
AnalizadaBaja (2.7)0.21%—Hcltech Domino Leap30/4/202517/6/2026
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
AnalizadaMedia (6.1)0.26%—Hcltech Domino Leap30/4/202517/6/2026
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
AnalizadaMedia (5.4)0.25%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
AnalizadaMedia (5.3)0.31%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
AnalizadaMedia (6.1)0.24%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
AnalizadaAlta (7.5)0.23%—Hcltech Domino Leap30/4/202517/6/2026
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
AnalizadaMedia (5.4)0.23%—Hcltech Domino Leap30/4/202517/6/2026
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
AnalizadaMedia (5.4)0.29%—Hcltech Domino Leap30/4/202517/6/2026
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
AnalizadaMedia (5.4)0.29%—Hcltech Domino Leap30/4/202517/6/2026
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
AnalizadaAlta (7.5)0.31%—Hcltech Nomad Server ON Domino1/10/202417/6/2026
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
AnalizadaMedia (6.5)0.40%—Hcltech Nomad Server ON Domino25/9/202417/6/2026
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.
AnalizadaAlta (7.5)0.29%—Hcltech Nomad Server ON Domino19/7/202417/6/2026
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.
ModificadaAlta (7.5)0.47%—Hcltech Domino8/7/202417/6/2026
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.
ModificadaMedia (6.5)0.34%—Hcltech Nomad Server ON Domino5/7/202417/6/2026
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
AplazadaAlta (8.4)0.42%—CA Sitemanager WEB Agent FOR IISAICA Sitemanager WEB Agent FOR DominoAI14/6/202417/6/2026
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
ModificadaMedia (5.4)0.31%—Hcltech Domino6/6/202417/6/2026
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
AnalizadaMedia (5.9)0.47%—Hcltech Domino29/2/202417/6/2026
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password,…
ModificadaMedia (5.3)0.39%—Hcltech Domino8/9/202317/6/2026
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
ModificadaMedia (5.3)0.45%—HCL Domino Appdev Pack23/5/202317/6/2026
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users.
ModificadaAlta (8)0.70%—Domino Project Domino11/1/202317/6/2026
A vulnerability was found in dobos domino. It has been rated as critical. Affected by this issue is some unknown functionality in the library src/Complex.Domino.Lib/Lib/EntityFactory.cs. The manipulation leads to sql injection. Upgrading to version 0.1.5524.38553 is able to address this issue. The name of the patch is…
ModificadaAlta (7.8)0.69%—Hcltech Domino19/12/202217/6/2026
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This…
ModificadaAlta (7.8)0.69%—Hcltech Domino19/12/202217/6/2026
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.