CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 46222 CVEs

CVE ID Severity Description EPSS Published
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

0.0% 2026-02-05
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Comply.

0.0% 2026-02-05
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Discover.

0.0% 2026-02-05
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

0.0% 2026-02-05
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Patch.

0.0% 2026-02-05
6.5 MEDIUM

Tanium addressed an incorrect default permissions vulnerability in Performance.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an information disclosure vulnerability in Threat Response.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an information disclosure vulnerability in Threat Response.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an information disclosure vulnerability in Threat Response.

0.0% 2026-02-05
4.9 MEDIUM

Tanium addressed an information disclosure vulnerability in Threat Response.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an uncontrolled resource consumption vulnerability in Connect.

0.0% 2026-02-05
8.8 HIGH

Tanium addressed an improper input validation vulnerability in Deploy.

0.0% 2026-02-05
4.9 MEDIUM

Tanium addressed an information disclosure vulnerability in Threat Response.

0.0% 2026-02-05
5.0 MEDIUM

Tanium addressed an improper link resolution before file access vulnerability in Enforce.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an improper access controls vulnerability in Deploy.

0.0% 2026-02-05
4.3 MEDIUM

Tanium addressed an improper access controls vulnerability in Patch.

0.0% 2026-02-05
6.3 MEDIUM

Tanium addressed an improper input validation vulnerability in Discover.

0.0% 2026-02-05
6.6 MEDIUM

Tanium addressed a documentation issue in Engage.

0.0% 2026-02-05
3.7 LOW

Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.

0.0% 2026-02-05
2.7 LOW

Tanium addressed an improper input validation vulnerability in Tanium Appliance.

0.0% 2026-02-05
6.6 MEDIUM

Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.

0.0% 2026-02-05
7.8 HIGH

Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

0.0% 2026-02-05
3.1 LOW

Tanium addressed an improper access controls vulnerability in Interact.

0.0% 2026-02-05
7.4 HIGH

pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in real time, and race the restore process by overwriting the restore script with a payload that re-enables meta-commands using `\unrestrict <key>`. This results in reliable command execution on the pgAdmin host during the restore operation.

0.0% 2026-02-05
7.2 HIGH

An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function

0.5% 2026-02-05
10.0 CRITICAL

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

0.0% 2026-02-05
5.3 MEDIUM

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

0.0% 2026-02-05
5.3 MEDIUM

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

0.0% 2026-02-05
8.8 HIGH

An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.

0.0% 2026-02-05
5.6 MEDIUM

The response coming from TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.

0.0% 2026-02-05
6.8 MEDIUM

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.

0.0% 2026-02-05
6.8 MEDIUM

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.

0.0% 2026-02-05
6.1 MEDIUM

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

0.0% 2026-02-05
6.1 MEDIUM

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

0.0% 2026-02-05
8.8 HIGH

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

0.1% 2026-02-05
5.5 MEDIUM

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

0.0% 2026-02-05
9.0 CRITICAL

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File name parameter in the WebMail Listeners SSL settings. Attackers can inject malicious JavaScript payloads that execute in administrators' browsers when they access affected pages or features, enabling privilege escalation attacks where low-privileged admins can force high-privileged admins to perform unauthorized actions.

0.0% 2026-02-05
5.4 MEDIUM

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by exploiting a separate vulnerability or using compromised credentials. In the second stage, when the victim logs into the WebMail interface, the unsanitized timeFormat value is loaded from storage and inserted into the DOM, causing the injected script to execute.

0.0% 2026-02-05
6.1 MEDIUM

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.

0.0% 2026-02-05
7.5 HIGH

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.

0.1% 2026-02-05
8.1 HIGH

Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.

0.0% 2026-02-05
3.5 LOW

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser session in the context of the affected site. This can be exploited by submitting crafted input to the label modification functionality, such as the 'lab4' parameter in config.html.

0.0% 2026-02-05
4.3 MEDIUM

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

0.0% 2026-02-05
5.3 MEDIUM

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

0.0% 2026-02-05
7.5 HIGH

ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication.

0.0% 2026-02-05
8.4 HIGH

10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code execution.

0.0% 2026-02-05
5.5 MEDIUM

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

0.0% 2026-02-05
8.4 HIGH

Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields, causing the application to crash.

0.0% 2026-02-05
9.8 CRITICAL

10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution prevention through a ROP chain.

0.1% 2026-02-05
6.1 MEDIUM

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.

0.0% 2026-02-05