Search

Search Results (331342 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-15330 1 Tanium 1 Service Deploy 2026-02-05 8.8 High
Tanium addressed an improper input validation vulnerability in Deploy.
CVE-2025-15329 1 Tanium 1 Service Threatresponse 2026-02-05 4.9 Medium
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15328 1 Tanium 1 Service Enforce 2026-02-05 5 Medium
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
CVE-2025-15327 1 Tanium 1 Service Deploy 2026-02-05 4.3 Medium
Tanium addressed an improper access controls vulnerability in Deploy.
CVE-2025-15326 1 Tanium 1 Service Patch 2026-02-05 4.3 Medium
Tanium addressed an improper access controls vulnerability in Patch.
CVE-2025-15325 1 Tanium 1 Service Discover 2026-02-05 6.3 Medium
Tanium addressed an improper input validation vulnerability in Discover.
CVE-2025-15324 1 Tanium 1 Service Engage 2026-02-05 6.6 Medium
Tanium addressed a documentation issue in Engage.
CVE-2025-15323 1 Tanium 1 Tanos 2026-02-05 3.7 Low
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
CVE-2025-15321 1 Tanium 1 Tanos 2026-02-05 2.7 Low
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
CVE-2025-15312 1 Tanium 1 Tanos 2026-02-05 6.6 Medium
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
CVE-2025-15311 1 Tanium 1 Tanos 2026-02-05 7.8 High
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
CVE-2025-15289 1 Tanium 1 Service Interact 2026-02-05 3.1 Low
Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-62840 2 Qnap, Qnap Systems Inc. 2 Hybrid Backup Sync, Hbs 3 Hybrid Backup Sync 2026-02-05 3.3 Low
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
CVE-2025-62842 2 Qnap, Qnap Systems Inc. 2 Hybrid Backup Sync, Hbs 3 Hybrid Backup Sync 2026-02-05 7.8 High
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
CVE-2025-20903 1 Samsung 1 Android 2026-02-05 7.3 High
Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
CVE-2026-23844 2 Whisper-money, Whisper.money 2 Whisper-money, Whisper Money 2026-02-05 4.3 Medium
Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other users' bank accounts. Version 0.1.5 fixes the issue.
CVE-2025-20908 1 Samsung 1 Android 2026-02-05 6.5 Medium
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
CVE-2026-23846 1 Quenary 1 Tugtainer 2026-02-05 8.1 High
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and proxy logs. Version 1.16.1 patches the issue.
CVE-2020-37133 2026-02-05 7.5 High
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.
CVE-2020-37132 2026-02-05 6.2 Medium
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.