CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-15333

    Last Modified: 10 Feb 2026

    Tanium addressed an information disclosure vulnerability in Threat Response.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15334

    Last Modified: 10 Feb 2026

    Tanium addressed an information disclosure vulnerability in Threat Response.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15335

    Last Modified: 10 Feb 2026

    Tanium addressed an information disclosure vulnerability in Threat Response.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15341

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Benchmark.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15339

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Discover.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15340

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Comply.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15338

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15336

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Performance.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15337

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Patch.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15342

    Last Modified: 10 Feb 2026

    Tanium addressed an improper access controls vulnerability in Reputation.

    Published: 5 Feb 2026
    3.7
    Low

    CVE-2025-15323

    Last Modified: 10 Feb 2026

    Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2025-15343

    Last Modified: 10 Feb 2026

    Tanium addressed an incorrect default permissions vulnerability in Enforce.

    Published: 5 Feb 2026
    3.1
    Low

    CVE-2025-15289

    Last Modified: 10 Feb 2026

    Tanium addressed an improper access controls vulnerability in Interact.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2025-58190

    Last Modified: 18 Feb 2026

    The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2025-47911

    Last Modified: 18 Feb 2026

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

    Published: 5 Feb 2026
    10
    Critical

    CVE-2025-68121

    Last Modified: 29 Apr 2026

    During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

    Published: 5 Feb 2026
    7.5
    High

    CVE-2025-15557

    Last Modified: 12 Feb 2026

    An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.

    Published: 5 Feb 2026
    7.4
    High

    CVE-2026-1707

    Last Modified: 26 Feb 2026

    pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in real time, and race the restore process by overwriting the restore script with a payload that re-enables meta-commands using `\unrestrict <key>`. This results in reliable command execution on the pgAdmin host during the restore operation.

    Published: 5 Feb 2026
    5.9
    Medium

    CVE-2025-15551

    Last Modified: 22 Apr 2026

    The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.

    Published: 5 Feb 2026
    7
    High

    CVE-2026-0715

    Last Modified: 18 Apr 2026

    Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.

    Published: 5 Feb 2026
    7
    High

    CVE-2026-0714

    Last Modified: 17 Apr 2026

    A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37148

    Last Modified: 15 Apr 2026

    P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser session in the context of the affected site. This can be exploited by submitting crafted input to the label modification functionality, such as the 'lab4' parameter in config.html.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37152

    Last Modified: 5 Mar 2026

    PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.

    Published: 5 Feb 2026
    8.7
    High

    CVE-2020-37150

    Last Modified: 5 Mar 2026

    Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37149

    Last Modified: 5 Mar 2026

    Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37145

    Last Modified: 15 Apr 2026

    HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37144

    Last Modified: 15 Apr 2026

    Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

    Published: 5 Feb 2026
    4.6
    Medium

    CVE-2020-37143

    Last Modified: 15 Apr 2026

    ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37142

    Last Modified: 15 Apr 2026

    10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code execution.

    Published: 5 Feb 2026
    4.6
    Medium

    CVE-2020-37140

    Last Modified: 27 Mar 2026

    Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

    Published: 5 Feb 2026
    4.6
    Medium

    CVE-2020-37139

    Last Modified: 15 Apr 2026

    Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields, causing the application to crash.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37138

    Last Modified: 15 Apr 2026

    10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution prevention through a ROP chain.

    Published: 5 Feb 2026
    8.6
    High

    CVE-2020-37137

    Last Modified: 15 Jul 2026

    PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37136

    Last Modified: 15 Jul 2026

    ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files.

    Published: 5 Feb 2026
    4.6
    Medium

    CVE-2020-37134

    Last Modified: 15 Apr 2026

    UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37133

    Last Modified: 9 Feb 2026

    UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37132

    Last Modified: 9 Feb 2026

    UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37131

    Last Modified: 26 Mar 2026

    Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37130

    Last Modified: 15 Jul 2026

    Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.

    Published: 5 Feb 2026
    8.5
    High

    CVE-2020-37129

    Last Modified: 15 Apr 2026

    Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37128

    Last Modified: 15 Jul 2026

    ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37126

    Last Modified: 15 Apr 2026

    Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Handler (SEH) registers. Attackers can exploit the vulnerability by crafting a malicious Unicode input that triggers an access violation and potentially execute arbitrary code.

    Published: 5 Feb 2026
    6.9
    Medium

    CVE-2020-37127

    Last Modified: 15 Apr 2026

    Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.

    Published: 5 Feb 2026
    9.3
    Critical

    CVE-2020-37125

    Last Modified: 5 Mar 2026

    Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37124

    Last Modified: 15 Apr 2026

    B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during base64 decoding process.

    Published: 5 Feb 2026
    9.3
    Critical

    CVE-2020-37123

    Last Modified: 15 Apr 2026

    Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.

    Published: 5 Feb 2026
    6.7
    Medium

    CVE-2020-37121

    Last Modified: 6 Aug 2026

    CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious text file with 1982 bytes of buffer and shellcode to trigger remote code execution.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37120

    Last Modified: 15 Apr 2026

    Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and triggering remote code execution.

    Published: 5 Feb 2026
    8.4
    High

    CVE-2020-37119

    Last Modified: 7 Apr 2026

    Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit.

    Published: 5 Feb 2026
    5.1
    Medium

    CVE-2020-37118

    Last Modified: 15 Apr 2026

    P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted page.

    Published: 5 Feb 2026