HCL / AION
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-21833 | HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833) | LOW | 3.7 | Oct 1, 2026 |
| CVE-2026-21832 | HCL AION is affected by multiple security vulnerabilities. | MEDIUM | 4.3 | Aug 13, 2026 |
| CVE-2025-62315 | HCL AION is affected by multiple security vulnerabilities. | LOW | 3.4 | Aug 13, 2026 |
| CVE-2025-62318 | HCL AION is affected by multiple security vulnerabilities. | LOW | 3.7 | Aug 13, 2026 |
| CVE-2025-62314 | HCL AION is affected by multiple security vulnerabilities. | MEDIUM | 5.6 | Aug 13, 2026 |
| CVE-2025-52640 | HCL AION is affected by multiple security vulnerabilities. | MEDIUM | 4.7 | Aug 13, 2026 |
| CVE-2025-62305 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions | MEDIUM | 5.1 | May 14, 2026 |
| CVE-2025-62317 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. | LOW | 2.6 | May 14, 2026 |
| CVE-2025-62308 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed | MEDIUM | 5.1 | May 14, 2026 |
| CVE-2025-62309 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. | LOW | 2.6 | May 14, 2026 |
| CVE-2025-62312 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication | LOW | 3.0 | May 14, 2026 |
| CVE-2025-62316 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured | LOW | 2.3 | May 14, 2026 |
| CVE-2025-62313 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. | MEDIUM | 5.4 | May 14, 2026 |
| CVE-2025-62311 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. | MEDIUM | 4.3 | May 14, 2026 |
| CVE-2025-62310 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations | MEDIUM | 5.4 | May 14, 2026 |
| CVE-2025-52641 | Internal Filesystem Exploration vulnerability | MEDIUM | 5.3 | Apr 15, 2026 |
| CVE-2025-52642 | HCL AION is affected by an internal filesystem paths disloser vulnerability | MEDIUM | 6.5 | Mar 16, 2026 |
| CVE-2025-52646 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. | MEDIUM | 5.3 | Mar 16, 2026 |
| CVE-2025-52645 | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. | MEDIUM | 5.3 | Mar 16, 2026 |
| CVE-2025-52649 | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature | MEDIUM | 5.3 | Mar 16, 2026 |
| CVE-2025-52644 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. | HIGH | 8.2 | Mar 16, 2026 |
| CVE-2025-52643 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment | HIGH | 7.8 | Mar 16, 2026 |
| CVE-2025-52636 | HCL AION is affected by a improper handling of uploads files Size | HIGH | 7.5 | Mar 16, 2026 |
| CVE-2025-52648 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered image… | CRITICAL | 9.8 | Mar 16, 2026 |
| CVE-2025-52638 | Multiple security vulnerabilities affect HCL AION | HIGH | 7.2 | Mar 16, 2026 |
Showing 1 to 25 of 45 CVEs