|
931
|
8.1 |
HIGH
Network
|
hashicorp
|
vault
|
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulne…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-3605
|
2026-04-26 03:08 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2025-52660
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibili…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de encabezados de respuesta de seguridad faltantes. La ausencia de encabezados de seguridad estándar puede debilitar la postura de seguridad general de l…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-55249
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad de carga de archivos sin restricciones. Esto puede permitir cargas de archivos maliciosos, lo que podría resultar en ejecución de código no autorizada o …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-55251
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
HCL AION versión 2 está afectado por una vulnerabilidad de política de contraseñas débil. Esto puede permitir el uso de contraseñas fácilmente adivinables, lo que podría resultar en acceso no autoriz…
|
CWE-521
Weak Password Requirements
|
CVE-2025-55252
|
2026-04-26 03:05 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2025-55250
|
2026-04-26 03:04 |
2026-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|