Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.6 CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters._CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it...

HCL AION 2.1.0 CVE
LOW 2.3 CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured_CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers ...

HCL AION 2.1.0 CVE
LOW 3 CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication_CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may exp...

HCL AION 2.1.0 CVE
LOW 2.6 CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields._CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information...

HCL AION 2.1.0 CVE
LOW 3.7 CVE-2026-6638

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name_CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary S...

n/a PostgreSQL 18 CVE
LOW 3.5 CVE-2026-7471

Server-Side Request Forgery (SSRF) in GitLab_CVE-2026-7471

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 18.8 CVE
LOW 2.6 CVE-2026-6883

Missing Authorization in GitLab_CVE-2026-6883

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 15.7 CVE
LOW 2.7 CVE-2026-2900

Missing Authorization in GitLab_CVE-2026-2900

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that wh...

GitLab GitLab 16.10 CVE
LOW 2.9 CVE-2026-42578

Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation_CVE-2026-42578

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs ...

netty netty >= 4.2.0.Alpha1, < 4.2.13.Final CVE
LOW 1.8 CVE-2026-30904

CVE-2026-30904_CVE-2026-30904

Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information ...

Zoom Communications Zoom Workplace CVE