Search

Search Results (331354 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-22030 1 Shopify 2 React-router, Remix-run\/react 2026-02-05 6.5 Medium
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/server-runtime version 2.17.3 and react-router version 7.12.0.
CVE-2020-37150 2026-02-05 7.5 High
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
CVE-2020-37137 2026-02-05 6.1 Medium
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.
CVE-2020-37117 2026-02-05 8.8 High
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
CVE-2025-15557 2026-02-05 N/A
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.
CVE-2025-70073 2026-02-05 N/A
An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function
CVE-2026-1707 2026-02-05 7.4 High
pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in real time, and race the restore process by overwriting the restore script with a payload that re-enables meta-commands using `\unrestrict <key>`. This results in reliable command execution on the pgAdmin host during the restore operation.
CVE-2025-58190 2026-02-05 N/A
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
CVE-2025-47911 2026-02-05 N/A
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
CVE-2025-15323 1 Tanium 1 Tanos 2026-02-05 3.7 Low
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
CVE-2025-15324 1 Tanium 1 Service Engage 2026-02-05 6.6 Medium
Tanium addressed a documentation issue in Engage.
CVE-2025-15330 1 Tanium 1 Service Deploy 2026-02-05 8.8 High
Tanium addressed an improper input validation vulnerability in Deploy.
CVE-2025-15331 1 Tanium 1 Service Connect 2026-02-05 4.3 Medium
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
CVE-2025-15332 1 Tanium 1 Service Threatresponse 2026-02-05 4.9 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15334 1 Tanium 1 Service Threatresponse 2026-02-05 4.3 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15335 1 Tanium 1 Service Threatresponse 2026-02-05 4.3 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15336 1 Tanium 1 Service Performance 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Performance.
CVE-2025-15338 1 Tanium 1 Service Partnerintegration 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
CVE-2025-15339 1 Tanium 1 Service Discover 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Discover.
CVE-2025-15342 1 Tanium 1 Service Reputation 2026-02-05 4.3 Medium
Tanium addressed an improper access controls vulnerability in Reputation.