Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability_CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness i...

HCL BigFix RunBookAI 11.2 CVE
LOW 3.1 CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability_CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protectio...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.1 CVE-2025-59853

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability_CVE-2025-59853

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which co...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.7 CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability_CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encry...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.7 CVE-2025-59851

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability_CVE-2025-59851

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-compon...

HCL DFXAnalytics 3.1 and below CVE
LOW 3.4 CVE-2026-44405

CVE-2026-44405_CVE-2026-44405

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

Paramiko Paramiko CVE
LOW 2 CVE-2026-34527

Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction_CVE-2026-34527

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts...

sandboxie-plus Sandboxie < 1.17.3 CVE
LOW 2.1 CVE-2026-7846

chatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py files toctou_CVE-2026-7846

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/...

chatchat-space Langchain-Chatchat 0.3.1.0 CVE
LOW 2.1 CVE-2026-7845

chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash_CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatch...

chatchat-space Langchain-Chatchat 0.3.1.0 CVE
LOW 2.3 CVE-2026-35192

Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST_CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSI...

djangoproject Django 6.0 CVE