Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-1196

MineAdmin getFileInfoById information disclosure_CVE-2026-1196

A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipula...

n/a MineAdmin 1.x CVE
LOW 2.3 CVE-2026-1195

MineAdmin JWT Token refresh data authenticity_CVE-2026-1195

A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handl...

n/a MineAdmin 1.x CVE
LOW 2.1 CVE-2026-23847

SiYuan Vulnerable to Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon_CVE-2026-23847

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicI...

siyuan-note siyuan < 3.5.4 CVE
LOW 3.1 CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability_CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized cod...

HCL Software AION 2 CVE
LOW 2.7 CVE-2025-52660

HCL AION is affected by an Host Header Injection vulnerability_CVE-2025-52660

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized cod...

HCL Software AION 2 CVE
LOW 2.8 CVE-2025-52659

HCL AION is affected by a Cacheable HTTP Response vulnerability_CVE-2025-52659

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, pot...

HCL Software AION 2 CVE
LOW 1.7 CVE-2026-23833

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component_CVE-2026-23833

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2025.12.6, an integer overfl...

esphome esphome >= 2025.9.0, < 2025.12.7 CVE
LOW 3.5 CVE-2025-55249

HCL AION is affected by a Missing Security Response Headers vulnerability._CVE-2025-55249

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s ov...

HCL Software AION 2 CVE
LOW 2.4 CVE-2025-52661

CVE-2025-52661_CVE-2025-52661

HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in u...

HCL Software AION 2 CVE
LOW 3.1 CVE-2025-55252

HCL AION is affected by a Weak Password Policy vulnerability_CVE-2025-55252

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulti...

HCL Software AION 2 CVE