Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.6 CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified._CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal...

HCL BigFix Service Management (SM) 23 CVE
LOW 3.5 CVE-2025-31959

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images._CVE-2025-31959

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy r...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 2.6 CVE-2025-31957

HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability._CVE-2025-31957

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or e...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 2.7 CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability_CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness i...

HCL BigFix RunBookAI 11.2 CVE
LOW 3.1 CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability_CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protectio...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.1 CVE-2025-59853

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability_CVE-2025-59853

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which co...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.7 CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability_CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encry...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.7 CVE-2025-59851

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability_CVE-2025-59851

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-compon...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.4 CVE-2026-44405

CVE-2026-44405_CVE-2026-44405

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

Paramiko Paramiko CVE
LOW 2 CVE-2026-34527

Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction_CVE-2026-34527

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts...

sandboxie-plus Sandboxie < 1.17.3 CVE