Search

Search Results (331577 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-1162 1 Utt 3 810, 810 Firmware, Hiper 810 2026-02-06 9.8 Critical
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2026-25505 1 Maziggy 1 Bambuddy 2026-02-06 9.8 Critical
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
CVE-2025-47283 1 Gardener 1 Gardener 2026-02-06 9.9 Critical
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters. `gardener/gardener` (`gardenlet`) is the affected component. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.
CVE-2025-15329 1 Tanium 1 Service Threatresponse 2026-02-06 4.9 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15331 1 Tanium 1 Service Connect 2026-02-06 4.3 Medium
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
CVE-2025-15330 1 Tanium 1 Service Deploy 2026-02-06 8.8 High
Tanium addressed an improper input validation vulnerability in Deploy.
CVE-2025-15328 1 Tanium 1 Service Enforce 2026-02-06 5 Medium
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
CVE-2025-15327 1 Tanium 1 Service Deploy 2026-02-06 4.3 Medium
Tanium addressed an improper access controls vulnerability in Deploy.
CVE-2025-15326 1 Tanium 1 Service Patch 2026-02-06 4.3 Medium
Tanium addressed an improper access controls vulnerability in Patch.
CVE-2025-15325 1 Tanium 1 Service Discover 2026-02-06 6.3 Medium
Tanium addressed an improper input validation vulnerability in Discover.
CVE-2025-15324 1 Tanium 1 Service Engage 2026-02-06 6.6 Medium
Tanium addressed a documentation issue in Engage.
CVE-2025-14472 2 Acquia, Drupal 2 Acquia Content Hub, Acquia Content Hub 2026-02-06 8.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from 3.7.0 before 3.7.3.
CVE-2025-13984 2 Drupal, Kanopi 2 Next.js, Next.js 2026-02-06 6.1 Medium
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
CVE-2025-15312 1 Tanium 1 Tanos 2026-02-06 6.6 Medium
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
CVE-2025-15311 1 Tanium 1 Tanos 2026-02-06 7.8 High
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
CVE-2025-13986 2 Drupal, Zyxware 2 Disable Login Page, Disable Login Page 2026-02-06 4.2 Medium
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3.
CVE-2025-13985 2 Drupal, Ithom 2 Entity Share, Entity Share 2026-02-06 5.3 Medium
Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.
CVE-2025-14840 2 Bmeme, Drupal 2 Http Client Manager, Http Client Manager 2026-02-06 7.5 High
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.
CVE-2025-61726 2 Go Standard Library, Golang 2 Net/url, Go 2026-02-06 7.5 High
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
CVE-2025-61728 2 Go Standard Library, Golang 2 Archive/zip, Go 2026-02-06 6.5 Medium
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.