Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-40243

Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation_CVE-2026-40243

Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic...

lxc incus < 7.0.0 CVE
LOW 3.9 CVE-2025-31974

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only_CVE-2025-31974

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may all...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 3.7 CVE-2025-31984

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header_CVE-2025-31984

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This c...

HCL BigFix Service Management (SM) 23 CVE
LOW 3.7 CVE-2025-31983

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header_CVE-2025-31983

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to injec...

HCL BigFix Service Management (SM) 23 CVE
LOW 3.7 CVE-2025-31982

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl_CVE-2025-31982

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an inc...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 2.6 CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified._CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal...

HCL BigFix Service Management (SM) 23 CVE
LOW 3.5 CVE-2025-31959

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images._CVE-2025-31959

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy r...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 2.6 CVE-2025-31957

HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability._CVE-2025-31957

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or e...

HCL Software BigFix Service Management (SM) 23 CVE
LOW 2.7 CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability_CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness i...

HCL BigFix RunBookAI 11.2 CVE
LOW 3.1 CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability_CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protectio...

HCL DFXAnalytics 3.1 and below CVE