Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.37% | — | Hcltech HCL Digital Experience | 19/12/2022 | 17/6/2026 | In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. | |
| Modificada | Media (5.4) | 0.41% | — | Hcltech HCL Digital Experience | 22/9/2022 | 17/6/2026 | User input included in error response, which could be used in a phishing attack. | |
| Modificada | Media (6.1) | 0.64% | — | Hcltech HCL Digital Experience | 5/11/2020 | 17/6/2026 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | |
| Modificada | Crítica (9.8) | 1.1% | — | Hcltech HCL Digital Experience | 11/6/2020 | 17/6/2026 | "HCL Digital Experience is susceptible to Server Side Request Forgery." |