Aion

Vendor:

First CVE: Oct 10, 2025 · Active for under a year

29
Total CVEs
More Total CVEs than 96% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Aion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2025
9 months ago
Most Recent CVE
Apr 15, 2026
100 days ago

CVE Severity & Scoring

Aion29 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (3.4%)
Network28 (96.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None24 (82.8%)
Unknown0 (0.0%)
Required5 (17.2%)
Privileges Required
Low1 (3.4%)
High0 (0.0%)
None28 (96.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Jan 19, 20269.834NONO
HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access
Jan 19, 20269.833NONO
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Jan 19, 20269.833NONO
A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.
Oct 10, 20259.833NONO
A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.Thi
Feb 3, 20269.829NONO
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorize
Jan 19, 20267.528NONO
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user a
Mar 16, 20268.225NONO
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing expos
Feb 3, 20268.825NONO
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, whic
Mar 16, 20267.524NONO
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to
Mar 16, 20267.824NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Aion

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.0217.50.2%00