VendorsHcltechaion2.0.0
Vulnerabilities

Hcltech Aion 2.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2025-52626
HCL AION is susceptible to Potential Command Injection vulnerability
Published 2026-02-03 · Analyzed
9.8EPSS 0.006
CVE-2025-52660
HCL AION is affected by an Host Header Injection vulnerability
Published 2026-01-19 · Analyzed
9.8EPSS 0.003
CVE-2025-52635
HCL AION is susceptible to Trusted types in scripts not enforced in CSP
Published 2025-10-10 · Analyzed
9.8EPSS 0.003
CVE-2025-55251
HCL AION is affected by an Unrestricted File Upload vulnerability
Published 2026-01-19 · Analyzed
9.8EPSS 0.002
CVE-2025-55252
HCL AION is affected by a Weak Password Policy vulnerability
Published 2026-01-19 · Analyzed
9.8EPSS 0.002
CVE-2025-52628
HCL AION is susceptible to Missing SameSite vulnerability
Published 2026-02-03 · Analyzed
8.8EPSS 0.002
CVE-2025-52650
HCL AION is susceptible to Inline script execution allowed in CSP vulnerability
Published 2025-10-10 · Analyzed
8.2EPSS 0.002
CVE-2025-52631
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.
Published 2026-02-03 · Analyzed
8.1EPSS 0.002
CVE-2025-52625
HCL AION is susceptible to Cacheable SSL Page Found vulnerability
Published 2025-10-10 · Analyzed
7.5EPSS 0.002
CVE-2025-52630
HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability
Published 2025-10-10 · Analyzed
7.5EPSS 0.002
CVE-2025-52634
HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed
Published 2025-10-10 · Analyzed
7.5EPSS 0.002
CVE-2025-52659
HCL AION is affected by a Cacheable HTTP Response vulnerability
Published 2026-01-19 · Analyzed
7.5EPSS 0.002
CVE-2025-52627
HCL AION is susceptible to Incorrect Permission Assignment for Critical Resource
Published 2026-02-03 · Analyzed
7.5EPSS 0.002
CVE-2025-52632
HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
Published 2025-10-10 · Analyzed
7.5EPSS 0.001
CVE-2025-52623
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2025-52624
HCL AION is susceptible to Bypass of the script allow list configuration vulnerability
Published 2025-10-10 · Analyzed
6.1EPSS 0.002
CVE-2025-52629
HCL AION is susceptible to Missing Content-Security-Policy
Published 2026-02-03 · Analyzed
6.1EPSS 0.001
CVE-2025-55249
HCL AION is affected by a Missing Security Response Headers vulnerability.
Published 2026-01-19 · Analyzed
5.3EPSS 0.002
CVE-2025-52633
HCL AION is susceptible to Missing Content-Security-Policy
Published 2026-02-03 · Analyzed
5.3EPSS 0.002
CVE-2025-52661
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
Published 2026-01-19 · Analyzed
5.3EPSS 0.002
CVE-2025-55250
HCL AION is affected by a Technical Error Disclosure vulnerability
Published 2026-01-19 · Analyzed
5.3EPSS 0.002