Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.45%—Hcltechsw HCL Commerce14/5/202417/6/2026
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
ModificadaCrítica (9.8)0.73%—Hcltechsw HCL Commerce12/12/202217/6/2026
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
ModificadaMedia (5)0.18%—Hcltechsw HCL Commerce30/7/202217/6/2026
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
ModificadaBaja (3.3)0.19%—Hcltechsw HCL Commerce6/5/202217/6/2026
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
ModificadaCrítica (9.1)1.2%—Hcltechsw HCL Commerce13/8/202117/6/2026
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
ModificadaCrítica (9.8)1.4%—Hcltechsw HCL Commerce12/1/202117/6/2026
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
ModificadaAlta (7.5)1.3%—Hcltechsw HCL Commerce12/1/202117/6/2026
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.