Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (3.5) | — | — | HCL Bigfix Service ManagementAI | 6/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior. | |
| En análisis | Baja (3.7) | 0.21% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | |
| En análisis | Media (5.3) | 0.24% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks. | |
| Aplazada | Baja (3.7) | 0.21% | — | HCL AionAI | 1/10/2026 | 2/10/2026 | HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the… | |
| En análisis | Media (4.3) | 0.16% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. | |
| Analizada | Alta (7.4) | 0.15% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation. | |
| Analizada | Baja (2.2) | 0.06% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting… | |
| Analizada | Alta (7.2) | 0.20% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data. | |
| Aplazada | Baja (3.1) | 0.10% | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers. | |
| Aplazada | Alta (8.8) | 0.30% | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data. | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | HCL Digital ExperienceAI | 1/10/2026 | 1/10/2026 | HCL Digital Experience is affected by improper input sanitation. This can result in HTML injection which could be leveraged in content spoofing from a trusted domain. Apply HCL Digital Experience 9.5 CF238 or later to address this. | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | HCL SametimeAI | 24/9/2026 | 24/9/2026 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability. | |
| En análisis | Baja (3.1) | 0.15% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation… | |
| En análisis | Baja (3.1) | 0.25% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets. | |
| En análisis | Baja (3.1) | 0.24% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of… | |
| En análisis | Media (6.5) | 0.45% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access. | |
| En análisis | Media (6.4) | 0.29% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise. | |
| En análisis | Media (5) | 0.16% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries. | |
| En análisis | Media (6.3) | 0.21% | — | Hclsoftware Appscan 360AI | 18/9/2026 | 18/9/2026 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification… | |
| En análisis | Alta (7.6) | 0.28% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users. | |
| En análisis | Alta (8.1) | 0.35% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. | |
| En análisis | Crítica (9.3) | 0.34% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 21/9/2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | |
| En análisis | Crítica (9.8) | 0.47% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile… |