Vulnerabilities (CVE)

Total 396949 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-15350 1 Anritsu 1 Vectorstar 2026-06-17 N/A 7.8 HIGH
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CHX files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27039.
CVE-2025-15349 1 Anritsu 1 Shockline 2026-06-17 N/A 7.5 HIGH
Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Anritsu ShockLine. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SCPI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27315.
CVE-2025-15348 1 Anritsu 1 Shockline 2026-06-17 N/A 7.8 HIGH
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu ShockLine. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CHX files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27833.
CVE-2025-15347 2026-06-17 N/A 8.8 HIGH
The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.
CVE-2025-15346 2026-06-17 N/A N/A
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced.  Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided.  This results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake.  The issue affects versions up to and including 5.8.2.
CVE-2025-15345 2026-06-17 N/A 6.1 MEDIUM
The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2025-15344 1 Tanium 1 Asset 2026-06-17 N/A 6.3 MEDIUM
Tanium addressed a SQL injection vulnerability in Asset.
CVE-2025-15343 1 Tanium 1 Enforce 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Enforce.
CVE-2025-15342 1 Tanium 1 Reputation 2026-06-17 N/A 4.3 MEDIUM
Tanium addressed an improper access controls vulnerability in Reputation.
CVE-2025-15341 1 Tanium 1 Benchmark 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
CVE-2025-15340 1 Tanium 1 Comply 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Comply.
CVE-2025-15339 1 Tanium 1 Discover 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Discover.
CVE-2025-15338 1 Tanium 1 Partner Integration 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
CVE-2025-15337 1 Tanium 1 Patch 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Patch.
CVE-2025-15336 1 Tanium 1 Performance 2026-06-17 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Performance.
CVE-2025-15335 1 Tanium 1 Threat Response 2026-06-17 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15334 1 Tanium 1 Threat Response 2026-06-17 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15333 1 Tanium 1 Threat Response 2026-06-17 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15332 1 Tanium 1 Threat Response 2026-06-17 N/A 4.9 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15331 1 Tanium 1 Connect 2026-06-17 N/A 4.3 MEDIUM
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.