Total
396949 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15350 | 1 Anritsu | 1 Vectorstar | 2026-06-17 | N/A | 7.8 HIGH |
| Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CHX files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27039. | |||||
| CVE-2025-15349 | 1 Anritsu | 1 Shockline | 2026-06-17 | N/A | 7.5 HIGH |
| Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Anritsu ShockLine. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SCPI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27315. | |||||
| CVE-2025-15348 | 1 Anritsu | 1 Shockline | 2026-06-17 | N/A | 7.8 HIGH |
| Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CHX files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27833. | |||||
| CVE-2025-15347 | 2026-06-17 | N/A | 8.8 HIGH | ||
| The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options. | |||||
| CVE-2025-15346 | 2026-06-17 | N/A | N/A | ||
| A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided. This results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake. The issue affects versions up to and including 5.8.2. | |||||
| CVE-2025-15345 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |||||
| CVE-2025-15344 | 1 Tanium | 1 Asset | 2026-06-17 | N/A | 6.3 MEDIUM |
| Tanium addressed a SQL injection vulnerability in Asset. | |||||
| CVE-2025-15343 | 1 Tanium | 1 Enforce | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Enforce. | |||||
| CVE-2025-15342 | 1 Tanium | 1 Reputation | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an improper access controls vulnerability in Reputation. | |||||
| CVE-2025-15341 | 1 Tanium | 1 Benchmark | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Benchmark. | |||||
| CVE-2025-15340 | 1 Tanium | 1 Comply | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Comply. | |||||
| CVE-2025-15339 | 1 Tanium | 1 Discover | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Discover. | |||||
| CVE-2025-15338 | 1 Tanium | 1 Partner Integration | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Partner Integration. | |||||
| CVE-2025-15337 | 1 Tanium | 1 Patch | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Patch. | |||||
| CVE-2025-15336 | 1 Tanium | 1 Performance | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tanium addressed an incorrect default permissions vulnerability in Performance. | |||||
| CVE-2025-15335 | 1 Tanium | 1 Threat Response | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an information disclosure vulnerability in Threat Response. | |||||
| CVE-2025-15334 | 1 Tanium | 1 Threat Response | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an information disclosure vulnerability in Threat Response. | |||||
| CVE-2025-15333 | 1 Tanium | 1 Threat Response | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an information disclosure vulnerability in Threat Response. | |||||
| CVE-2025-15332 | 1 Tanium | 1 Threat Response | 2026-06-17 | N/A | 4.9 MEDIUM |
| Tanium addressed an information disclosure vulnerability in Threat Response. | |||||
| CVE-2025-15331 | 1 Tanium | 1 Connect | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tanium addressed an uncontrolled resource consumption vulnerability in Connect. | |||||
