5.7
CVE-2025-37727 - Elasticsearch Insertion of sensitive information in log file
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
3.7
CVE-2025-52630 - HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
8.2
CVE-2025-25017 - Kibana Stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
7.3
CVE-2025-30001 - Apache StreamPark: Authenticated users can trigger remote command execution
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
8.7
CVE-2025-25018 - Kibana Stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
3.7
CVE-2025-52634 - HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AIONΒ This issue affects HCL AION: 2.0.
8.2
CVE-2025-52650 - HCL AION is susceptible to Inline script execution allowed in CSP vulnerability
Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
4.8
CVE-2025-41089 - Reflected Cross-Site Scripting (XSS) in CMS
Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock'β¦
5.1
CVE-2025-41088 - Stored Cross-Site Scripting (XSS) in CMS
Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Textβ¦
3.1
CVE-2025-52655 - HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.
Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.