Vulnerabilities

Summary — last 7 days

New vulnerabilities3,064▲ 562 vs. last week
Critical / high1,460▲ 282 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (4.3)0.22%—Hcltech Devops Loop7/17/20268/13/2026
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.
AnalyzedMedium (5.3)0.29%—Hcltech Devops Loop7/17/20268/13/2026
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.
AnalyzedMedium (5.4)0.20%—Hcltech Devops Loop7/17/20268/13/2026
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
AnalyzedMedium (4.6)0.21%—Hcltech Devops Loop7/17/20268/13/2026
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
AnalyzedMedium (6.5)0.33%—IBM Devops AutomationIBM Devops Loop6/30/20269/30/2026
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
DeferredHigh (8.1)0.19%—HCL Devops LoopAI11/5/20256/17/2026
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive…