Total
398152 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-62318 | 2026-08-28 | N/A | 3.7 LOW | ||
| HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | |||||
| CVE-2025-52640 | 2026-08-28 | N/A | 4.7 MEDIUM | ||
| HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions. | |||||
| CVE-2026-21766 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | |||||
| CVE-2026-78416 | 2026-08-28 | N/A | N/A | ||
| Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user. | |||||
| CVE-2026-21784 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. | |||||
| CVE-2026-16843 | 2026-08-28 | N/A | 7.2 HIGH | ||
| Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |||||
| CVE-2025-62347 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type. | |||||
| CVE-2025-62315 | 2026-08-28 | N/A | 3.4 LOW | ||
| HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | |||||
| CVE-2026-21832 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | |||||
| CVE-2025-62314 | 2026-08-28 | N/A | 5.6 MEDIUM | ||
| HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. | |||||
| CVE-2026-21809 | 2026-08-28 | N/A | 3.9 LOW | ||
| HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input. | |||||
| CVE-2026-21808 | 2026-08-28 | N/A | 4.1 MEDIUM | ||
| HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details. | |||||
| CVE-2026-56619 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input. | |||||
| CVE-2026-21810 | 2026-08-28 | N/A | 4.4 MEDIUM | ||
| HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary. | |||||
| CVE-2026-21807 | 2026-08-28 | N/A | 3.9 LOW | ||
| HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |||||
| CVE-2026-56620 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | |||||
| CVE-2026-78895 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78903 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 3.1 LOW |
| Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78908 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78912 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
