Export limit exceeded: 389515 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (389515 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87084 2026-09-09 7.7 High
Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-87075 2026-09-09 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87073 2026-09-09 6.5 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87072 2026-09-09 7.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87048 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047 2026-09-09 6.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87046 2026-09-09 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87037 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87036 2026-09-09 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-87034 2026-09-09 8.3 High
Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87033 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87032 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-87030 2026-09-09 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87025 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87023 2026-09-09 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87021 2026-09-09 7.2 High
Tanium addressed an unauthorized code execution vulnerability in Comply.
CVE-2026-87019 2026-09-09 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-86993 2026-09-09 N/A
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
CVE-2026-86078 2026-09-09 N/A
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process and disrupt later requests. The affected function is summarizeWorkflowStructure in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts. This issue is fixed in versions 2.37.7 and 2.38.2.