6.5
CVE-2026-2316 - chromium-browser: Insufficient policy enforcement in Frames
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
4.3
CVE-2025-15147 - WCFM Membership β WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Oβ¦
The WCFM Membership β WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled keβ¦
7.2
CVE-2026-0845 - WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Updβ¦
The WCFM β Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'WCFM_Settings_Controller::processing' function in β¦
5.5
CVE-2025-15314 - Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
5.5
CVE-2025-15313 - Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
7.8
CVE-2025-15310 - Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
5.1
CVE-2025-15318 - Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
7.8
CVE-2025-15319 - Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
7.7
CVE-2026-25958 - Cube privilege escalation via a specially crafted request
Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to privilege escalation. This vulnerability is fixed in 1.5.13, 1.4.2, and 1.0.14.
6.5
CVE-2026-25957 - Cube Denial of Service (DoS) - An authenticated attacker can crash the server by sending a speciallβ¦
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.