Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-23569

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23570

Publication date:
17/07/2026
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23571

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23572

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23573

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23574

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23575

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23577

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23564

Publication date:
17/07/2026
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23565

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23566

Publication date:
17/07/2026
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2024-23567

Publication date:
17/07/2026
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026