Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (6.3) | 0.21% | — | Hclsoftware Appscan 360AI | 18/9/2026 | 18/9/2026 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HCL Appscan PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Media (4.3) | 0.39% | — | HCL Appscan Traffic RecorderAI | 13/3/2025 | 17/6/2026 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the application is running. | |
| Analizada | Media (6.5) | 0.17% | — | Hcltech Appscan Source | 31/10/2024 | 17/6/2026 | HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. | |
| Modificada | Alta (7.8) | 0.17% | — | Hcltech Appscan Presence | 17/10/2023 | 17/6/2026 | An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges. | |
| Modificada | Alta (7.5) | 1.1% | — | Hcltech Appscan | 6/10/2020 | 17/6/2026 | "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | |
| Modificada | Media (5.3) | 0.54% | — | Hcltech Appscan | 6/10/2020 | 17/6/2026 | "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." | |
| Modificada | Media (6.1) | 0.65% | — | Hcltech Appscan | 7/7/2020 | 17/6/2026 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." | |
| Modificada | Media (4.3) | 0.75% | — | Hcltech Appscan | 7/7/2020 | 17/6/2026 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." | |
| Modificada | Alta (7.5) | 1.0% | — | Hcltech Appscan | 21/4/2020 | 17/6/2026 | "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | |
| Modificada | Crítica (9.8) | 1.0% | — | Hcltech Appscan | 7/4/2020 | 17/6/2026 | HCL AppScan Standard is vulnerable to excessive authorization attempts | |
| Modificada | Alta (8.2) | 1.2% | — | Hcltech Appscan | 7/4/2020 | 17/6/2026 | HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data | |
| Modificada | Crítica (9.8) | 1.4% | — | Hcltech Appscan | 14/2/2020 | 17/6/2026 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | |
| Modificada | Media (4.8) | 0.52% | — | Hcltech Appscan Source | 18/12/2019 | 17/6/2026 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | |
| Modificada | Alta (7.1) | 0.80% | — | Hcltech Appscan Source | 25/9/2019 | 17/6/2026 | HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in… | |
| Modificada | Media (5.4) | 0.64% | — | IBM Security Appscan | 16/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416. | |
| Modificada | Crítica (9.8) | 5.0% | — | IBM Rational Appscan SourceIBM Security Appscan Source | 12/4/2018 | 17/6/2026 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721. | |
| Modificada | Alta (8.1) | 1.4% | — | IBM Security Appscan | 2/8/2017 | 17/6/2026 | IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257 | |
| Modificada | Alta (7.3) | 2.6% | — | IBM Security Appscan | 1/2/2017 | 17/6/2026 | IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to execute arbitrary code on the system in the same context as… | |
| Modificada | Media (5.3) | 1.0% | — | IBM Security Appscan Source | 1/2/2017 | 17/6/2026 | IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. | |
| Modificada | Media (4.4) | 0.21% | — | IBM Security Appscan Source | 1/2/2017 | 17/6/2026 | IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily. | |
| Modificada | Alta (8.1) | 1.4% | — | IBM Appscan Source | 1/12/2016 | 17/6/2026 | IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (6.5) | 1.5% | — | IBM Security Appscan | 1/6/2016 | 17/6/2026 | IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5.8) | 0.52% | — | IBM Security Appscan | 2/2/2015 | 17/6/2026 | IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.2% | — | IBM Security Appscan | 2/2/2015 | 17/6/2026 | IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network. |