Hyland
16 CVEs tracked since 2018. Since Feb 2018, none of them reached CISA KEV.
Hyland CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-02 | 2 | 0 |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | null or fewer | |
| 2020-09 | 14 | 0 |
Products
The products that kept showing up in Hyland's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Hyland.
- CVE-2026-58127PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service9.8
- CVE-2026-58126PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service9.8
- CVE-2026-26339Hyland Alfresco Transformation Service Argument Injection RCE9.8
- CVE-2026-26338Hyland Alfresco Transformation Service SSRF9.8
- CVE-2026-26337Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF8.2
- CVE-2026-26336Hyland Alfresco Improper Authorization Arbitrary File Read7.5
- CVE-2026-26221Hyland OnBase Timer Service Unauthenticated .NET Remoting RCE9.8
- CVE-2025-0557Hyland Alfresco Community Edition URL s cross site scripting4.3
- CVE-2024-40347A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted pay...6.1
- CVE-2023-49964An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Inject...8.8
- CVE-2021-32828Regular expression Denial of Service in MooTools5.4
- CVE-2022-23342The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obta...5.3
- CVE-2020-25247An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.7.5
- CVE-2020-25248An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for re...7.5
- CVE-2020-25249An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically logs activity only w...5.3
The record
- Peak rank
- #38 in Sep 2020
- Busiest month shown
- Sep 2020, 14 CVEs
- Months with a KEV entry
- 0 since Feb 2018
- Monthly snapshots
- 2 since 2018