CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 6.3 | A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to version 8.21 is sufficient to resolve this issue. The identifier of the patch is 053bf1dfb76ef230db162c64a6ed50ebedf67eee. It is recommended to upgrade the affected component. |
| 1mo ago | 6.5 | A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Enforce. |
| 1mo ago | 4.3 | Tanium addressed an improper access controls vulnerability in Reputation. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Benchmark. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Comply. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Discover. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Partner Integration. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Patch. |
| 1mo ago | 6.5 | Tanium addressed an incorrect default permissions vulnerability in Performance. |
| 1mo ago | 4.3 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| 1mo ago | 4.3 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| 1mo ago | 4.3 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| 1mo ago | 4.9 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| 1mo ago | 4.3 | Tanium addressed an uncontrolled resource consumption vulnerability in Connect. |
| 1mo ago | 4.9 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| 1mo ago | 5 | Tanium addressed an improper link resolution before file access vulnerability in Enforce. |
| 1mo ago | 4.3 | Tanium addressed an improper access controls vulnerability in Deploy. |
| 1mo ago | 4.3 | Tanium addressed an improper access controls vulnerability in Patch. |
| 1mo ago | 6.3 | Tanium addressed an improper input validation vulnerability in Discover. |
| 1mo ago | 6.6 | Tanium addressed a documentation issue in Engage. |
| 1mo ago | 6.6 | Tanium addressed an improper output sanitization vulnerability in Tanium Appliance. |
| Exploit 1mo ago | 5.3 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. |
| Exploit 1mo ago | 5.3 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. |
| Exploit 1mo ago | 5.6 | The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge. |
| Exploit 1mo ago | 6.8 | Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface. Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible. |
| Exploit 1mo ago | 6.8 | A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible. |
| Exploit 1mo ago | 6.1 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. |
| Exploit 1mo ago | 6.1 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. |
| Exploit 1mo ago | 5.5 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. |