8.4
CVE-2025-61856 -
A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
6.5
CVE-2025-52632 - HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
5.7
CVE-2025-37727 - Elasticsearch Insertion of sensitive information in log file
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
3.7
CVE-2025-52630 - HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
8.2
CVE-2025-25017 - Kibana Stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
7.3
CVE-2025-30001 - Apache StreamPark: Authenticated users can trigger remote command execution
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
8.7
CVE-2025-25018 - Kibana Stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
3.7
CVE-2025-52634 - HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AIONΒ This issue affects HCL AION: 2.0.
8.2
CVE-2025-52650 - HCL AION is susceptible to Inline script execution allowed in CSP vulnerability
Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
4.8
CVE-2025-41089 - Reflected Cross-Site Scripting (XSS) in CMS
Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock'β¦