Skip to main content

CWE archive

CWE-1032 CVEs

Programmatic archive

4 CVEs tagged with CWE-10320 Critical, 1 High, 1 Medium, 2 Low, 0 Unrated.

CVE-2025-52629

Published Feb 3, 2026

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52635

Published Oct 10, 2025

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52624

Published Oct 10, 2025

A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, in…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52650

Published Oct 10, 2025

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1