6.5
CVE-2025-15337 - Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Patch.
4.3
CVE-2025-15342 - Tanium addressed an improper access controls vulnerability in Reputation.
Tanium addressed an improper access controls vulnerability in Reputation.
3.7
CVE-2025-15323 - Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
6.5
CVE-2025-15343 - Tanium addressed an incorrect default permissions vulnerability in Enforce.
Tanium addressed an incorrect default permissions vulnerability in Enforce.
3.1
CVE-2025-15289 - Tanium addressed an improper access controls vulnerability in Interact.
Tanium addressed an improper access controls vulnerability in Interact.
7.4
CVE-2025-68121 - Unexpected session resumption in crypto/tls
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returneβ¦
5.3
CVE-2025-58190 - Infinite parsing loop in golang.org/x/net
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
5.3
CVE-2025-47911 - Quadratic parsing complexity in golang.org/x/net/html
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
7.5
CVE-2025-15557 - Improper Certificate Validation in TP-Link Tapo H100 and P100 Allows Man-in-the-Middle Attack
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.Β This may compromise the confidentiality and integrity of device-to-cloud communication, enβ¦
7.4
CVE-2026-1707 - Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)
pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract theβ¦