Search

Search Results (331526 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-15343 1 Tanium 1 Service Enforce 2026-02-06 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Enforce.
CVE-2025-15323 1 Tanium 1 Tanos 2026-02-06 3.7 Low
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
CVE-2025-15342 1 Tanium 1 Service Reputation 2026-02-06 4.3 Medium
Tanium addressed an improper access controls vulnerability in Reputation.
CVE-2025-13601 2 Gnome, Redhat 33 Glib, Ceph Storage, Codeready Linux Builder and 30 more 2026-02-06 7.7 High
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
CVE-2025-15337 1 Tanium 1 Service Patch 2026-02-06 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Patch.
CVE-2025-15336 1 Tanium 1 Service Performance 2026-02-06 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Performance.
CVE-2026-1162 1 Utt 3 810, 810 Firmware, Hiper 810 2026-02-06 9.8 Critical
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2026-25505 1 Maziggy 1 Bambuddy 2026-02-06 9.8 Critical
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
CVE-2025-47283 1 Gardener 1 Gardener 2026-02-06 9.9 Critical
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters. `gardener/gardener` (`gardenlet`) is the affected component. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.
CVE-2025-15329 1 Tanium 1 Service Threatresponse 2026-02-06 4.9 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15331 1 Tanium 1 Service Connect 2026-02-06 4.3 Medium
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
CVE-2025-15330 1 Tanium 1 Service Deploy 2026-02-06 8.8 High
Tanium addressed an improper input validation vulnerability in Deploy.
CVE-2025-15328 1 Tanium 1 Service Enforce 2026-02-06 5 Medium
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
CVE-2025-15327 1 Tanium 1 Service Deploy 2026-02-06 4.3 Medium
Tanium addressed an improper access controls vulnerability in Deploy.
CVE-2025-15326 1 Tanium 1 Service Patch 2026-02-06 4.3 Medium
Tanium addressed an improper access controls vulnerability in Patch.
CVE-2025-15325 1 Tanium 1 Service Discover 2026-02-06 6.3 Medium
Tanium addressed an improper input validation vulnerability in Discover.
CVE-2025-15324 1 Tanium 1 Service Engage 2026-02-06 6.6 Medium
Tanium addressed a documentation issue in Engage.
CVE-2025-14472 2 Acquia, Drupal 2 Acquia Content Hub, Acquia Content Hub 2026-02-06 8.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from 3.7.0 before 3.7.3.
CVE-2025-13984 2 Drupal, Kanopi 2 Next.js, Next.js 2026-02-06 6.1 Medium
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
CVE-2025-15312 1 Tanium 1 Tanos 2026-02-06 6.6 Medium
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.