|
4901
|
7.8 |
HIGH
Local
|
getcomposer
|
composer
|
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she…
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2026-40176
|
2026-04-26 03:24 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4902
|
6.1 |
MEDIUM
Network
|
apostrophecms
|
apostrophecms sanitize-html
|
ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasse…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40186
|
2026-04-26 03:15 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4903
|
8.8 |
HIGH
Network
|
getcomposer
|
composer
|
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2026-40261
|
2026-04-26 03:12 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4904
|
8.1 |
HIGH
Network
|
hashicorp
|
vault
|
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulne…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-3605
|
2026-04-26 03:08 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4905
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4906
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4907
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibili…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4908
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de encabezados de respuesta de seguridad faltantes. La ausencia de encabezados de seguridad estándar puede debilitar la postura de seguridad general de l…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4909
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4910
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4911
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4912
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de política de contraseñas débil. Esto puede permitir el uso de contraseñas fácilmente adivinables, lo que podría resultar en acceso no autoriz…
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4913
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4914
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de revelación de errores técnicos. Esto puede exponer detalles técnicos sensibles, lo que podría resultar en revelación de información o facili…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4915
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4916
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectada por una vulnerabilidad de JWT Token Expiry Too Long. Esto puede aumentar el riesgo de uso indebido del token, lo que podría resultar en acceso no autorizado si el tok…
|
CWE-613
Insufficient Session Expiration
|
CVE-2025-52661
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4917
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or informa…
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52659
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4918
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectada por una vulnerabilidad de respuesta HTTP cacheable. Esto puede llevar al almacenamiento no intencionado de contenido sensible o dinámico, lo que podría resultar en ac…
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52659
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4919
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially le…
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4920
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION se ve afectado por una vulnerabilidad donde ciertos identificadores pueden ser predecibles por naturaleza. Los identificadores predecibles pueden permitir a un atacante inferir o adivinar va…
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4921
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modifie…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4922
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad donde los mecanismos de empaquetado y distribución de modelos podrían no incluir suficiente verificación de autenticidad. Esto podría permitir la posibil…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4923
|
7.8 |
HIGH
Local
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security …
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-52643
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4924
|
7.8 |
HIGH
Local
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad donde las operaciones de análisis de archivos no confiables no se ejecutan dentro de un entorno de sandbox debidamente aislado. Esto puede exponer la apl…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-52643
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4925
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-52636
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4926
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION se ve afectado por una vulnerabilidad relacionada con el manejo de los límites de tamaño de carga. Un control o validación inadecuados de los tamaños de carga puede permitir un consumo exces…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-52636
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4927
|
7.5 |
HIGH
Network
|
fedify
|
fedify\/fedify fedify\/vocab-runtime
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote doc…
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-34148
|
2026-04-26 03:03 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4928
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-21388
|
2026-04-26 03:02 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4929
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4930
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage es un framework abierto para construir portales de desarrolladores, y @backstage/backend-defaults proporciona las implementaciones y configuración predeterminadas para una aplicación backen…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4931
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encod…
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4932
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 1.20.1, una vulnerabilidad en el análisis de URL de SCM utilizado por las integraciones de Backstage …
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4933
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run throug…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4934
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 3.1.4, una plantilla de andamiaje maliciosa puede eludir el mecanismo de redacción de registros para …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4935
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4936
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.x antes de 4.4.1, existe potencial ejecución remota de código y robo de credenciales de cuenta debido a una vulnerabilidad de suplantación de identidad.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4937
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4938
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.0 antes de 4.4.1, la validación indebida de los parámetros de solicitud de la API permite la ejecución remota de código.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4939
|
9.8 |
CRITICAL
Network
|
filigran
|
openaev
|
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-24467
|
2026-04-26 03:00 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4940
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site r…
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4941
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION está afectado por una Cookie con vulnerabilidad de SameSite insegura, impropia o ausente. Esto puede permitir que las cookies se envíen en peticiones entre sitios, aumentando potencialmente …
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4942
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauth…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-52627
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4943
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
Vulnerabilidad de configuración: Sistema de archivos raíz no montado como solo lectura. Esto puede permitir modificaciones no intencionadas a archivos críticos del sistema, aumentando potencialmente …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-52627
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4944
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
A Potential Command Injection vulnerability in HCL AION.
An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AIO…
|
CWE-78
OS Command
|
CVE-2025-52626
|
2026-04-26 02:58 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4945
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
Una posible vulnerabilidad de inyección de comandos en HCL AION. Esto puede permitir la ejecución no intencionada de comandos, lo que podría llevar a acciones no autorizadas en el sistema subyacente.…
|
CWE-78
OS Command
|
CVE-2025-52626
|
2026-04-26 02:58 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4946
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
A vulnerability
Cacheable SSL Page Found vulnerability has been identified
in HCL AION.
Cached data may expose credentials, system identifiers, or internal file paths to attackers with access t…
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52625
|
2026-04-26 02:58 |
2025-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4947
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processe…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4948
|
7.5 |
HIGH
Network
|
-
|
-
|
Se identificó una vulnerabilidad en la lógica de descompresión de archivos RAR5 de la biblioteca libarchive, específicamente dentro de la ruta de procesamiento de archive_read_data(). Cuando se proce…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4949
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-31534
|
2026-04-25 15:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4950
|
6.5 |
MEDIUM
Network
|
-
|
-
|
MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrar…
|
CWE-74
Injection
|
CVE-2026-41319
|
2026-04-25 12:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|