Aion
Vendor:
First CVE: Oct 10, 2025 · Active for under a year
29
Total CVEs
More Total CVEs than 96% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Aion over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2025
9 months ago
Most Recent CVE
Apr 15, 2026
100 days ago
CVE Severity & Scoring
Aion29 CVEs
45%
38%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.4%)
Network28 (96.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None24 (82.8%)
Unknown0 (0.0%)
Required5 (17.2%)
Privileges Required
Low1 (3.4%)
High0 (0.0%)
None28 (96.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55251CRITICAL HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-55252CRITICAL HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-52660CRITICAL HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-52635CRITICAL A
rusted types in scripts not enforced in CSP vulnerability has been identified
in HCL AION.This issue affects AION: 2.0. | Oct 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-52626CRITICAL A Potential Command Injection vulnerability in HCL AION.
An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.Thi | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-52659HIGH HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorize | Jan 19, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-52644HIGH HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user a | Mar 16, 2026 | 8.2 | 25 | NO | NO |
CVE-2025-52628HIGH HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing expos | Feb 3, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-52636HIGH HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, whic | Mar 16, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-52643HIGH HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to | Mar 16, 2026 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Aion
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 21 | 7.5 | 0.2% | 0 | 0 |