| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-52661 | HCL AION 安全漏洞 | HCL Software | AION | Low | 2.4 | 2026-01-19 18:04:31 | Deep Dive |
| CVE-2025-55249 | HCL AION is affected by a Missing Security Response Headers vulnerability. | HCL Software | AION | Low | 3.5 | 2026-01-19 18:01:05 | Deep Dive |
| CVE-2025-52659 | HCL AION is affected by a Cacheable HTTP Response vulnerability | HCL Software | AION | Low | 2.8 | 2026-01-19 17:54:19 | Deep Dive |
| CVE-2025-52660 | HCL AION is affected by an Host Header Injection vulnerability | HCL Software | AION | Low | 2.7 | 2026-01-19 17:49:52 | Deep Dive |
| CVE-2025-55251 | HCL AION is affected by an Unrestricted File Upload vulnerability | HCL Software | AION | Low | 3.1 | 2026-01-19 17:39:26 | Deep Dive |
| CVE-2025-52625 | HCL AION is susceptible to Cacheable SSL Page Found vulnerability | HCL | AION | Low | 3.7 | 2025-10-10 10:28:53 | Deep Dive |
| CVE-2025-52624 | HCL AION is susceptible to Bypass of the script allow list configuration vulnerability | HCL | AION | Medium | 5.4 | 2025-10-10 10:25:33 | Deep Dive |
| CVE-2025-52635 | HCL AION is susceptible to Trusted types in scripts not enforced in CSP | HCL | AION | Low | 3.7 | 2025-10-10 10:21:30 | Deep Dive |
| CVE-2025-52632 | HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability | HCL | AION | Medium | 6.5 | 2025-10-10 10:06:05 | Deep Dive |
| CVE-2025-52630 | HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability | HCL | AION | Low | 3.7 | 2025-10-10 09:55:59 | Deep Dive |
| CVE-2025-52634 | HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed | HCL | HCL AION | Low | 3.7 | 2025-10-10 09:40:05 | Deep Dive |
| CVE-2025-52650 | HCL AION is susceptible to Inline script execution allowed in CSP vulnerability | HCL | HCL AION | High | 8.2 | 2025-10-10 09:30:14 | Deep Dive |