Search

Search Results (331345 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-15336 1 Tanium 1 Service Performance 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Performance.
CVE-2025-15338 1 Tanium 1 Service Partnerintegration 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
CVE-2025-15339 1 Tanium 1 Service Discover 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Discover.
CVE-2025-15342 1 Tanium 1 Service Reputation 2026-02-05 4.3 Medium
Tanium addressed an improper access controls vulnerability in Reputation.
CVE-2025-15343 1 Tanium 1 Service Enforce 2026-02-05 6.5 Medium
Tanium addressed an incorrect default permissions vulnerability in Enforce.
CVE-2020-37134 2026-02-05 7.5 High
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.
CVE-2026-1301 2026-02-05 N/A
In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated array before authentication, reliably crashing the process and corrupting memory.
CVE-2025-15289 1 Tanium 1 Service Interact 2026-02-05 3.1 Low
Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-15321 1 Tanium 1 Tanos 2026-02-05 2.7 Low
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
CVE-2025-15327 1 Tanium 1 Service Deploy 2026-02-05 4.3 Medium
Tanium addressed an improper access controls vulnerability in Deploy.
CVE-2025-15333 1 Tanium 1 Service Threatresponse 2026-02-05 4.3 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-12131 2026-02-05 N/A
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
CVE-2020-37120 2026-02-05 9.8 Critical
Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and triggering remote code execution.
CVE-2020-37118 2026-02-05 3.5 Low
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted page.
CVE-2020-37119 2026-02-05 9.8 Critical
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit.
CVE-2020-37121 2026-02-05 9.8 Critical
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.
CVE-2020-37123 2026-02-05 9.8 Critical
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.
CVE-2020-37124 2026-02-05 9.8 Critical
B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during base64 decoding process.
CVE-2020-37131 2026-02-05 6.2 Medium
Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.
CVE-2020-37132 2026-02-05 6.2 Medium
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.