CVE-2025-62309Low· 2.6▾ SunlitHCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific co…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62305Medium· 5.1HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information
CVE-2025-62308Medium· 5.1HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed
CVE-2025-59955Medium· 5.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases
CVE-2025-69132Medium· 6.5Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2026-100258Medium· 4.3In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
CVE-2026-97240High· 7.5Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.