Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

240 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7GitLab

Low [CVE-2026-4363] GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.

CVE-2026-4363
GitLab CE / EE
Mar 25, 2026
Low2.3Apache

Low [CVE-2026-32642] Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue.

CVE-2026-32642
MessagingActiveMQ
Mar 24, 2026
Low2.7QNAP

Low [CVE-2025-59383] buffer overflow vulnerability has been reported to affect Media Streaming Add-On.

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later Affected product named by the advisory: Media Streaming Add-on 500.1.x.

CVE-2025-59383
Unclassified
Mar 20, 2026
Low2.6VMware

Low [CVE-2026-22735] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE).

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVE-2026-22735
Unclassified
Mar 20, 2026
Low2.8NetApp

Low [CVE-2026-1485] GLib Vulnerability in NetApp Products

Multiple NetApp products incorporate GLib. GLib versions through 2.86.3 and 2.87.0 through 2.87.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-1485
Unclassified
Mar 20, 2026
Low2.5Fortinet

Low [CVE-2026-24641] NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0…

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

CVE-2026-24641
FortiWeb
Mar 10, 2026
Low3.4Fortinet

Low [CVE-2026-22629] FortiManager: improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4…

An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4 all versions, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4 all versions, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4 all versions, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions, FortiManager Cloud 6.4 all versions may allow an attacker to bypass bruteforce protections via exploitation of race conditions. The latter raises the complexity of practical exploitation.

CVE-2026-22629
FortiManagerFortiAnalyzer
Mar 10, 2026
Low3.8Vendor: MediumFortinet

Low [CVE-2025-55717] cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2…

A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.

CVE-2025-55717
FortiMail
Mar 10, 2026
Low2.3Commvault

Low OTP Invalidation Missing Upon Regeneration

OTP Invalidation Missing Upon Regeneration

Unclassified
Mar 2, 2026
Low2.7VMware

Low [CVE-2026-22717] Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

CVE-2026-22717
Workstation & Fusion
Feb 27, 2026
LowCommvault Exploited CISA KEV

Low [CVE-2025-14847] MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

CVE-2025-14847
Unclassified
Feb 10, 2026
Low3.3MS Server

Low [CVE-2026-21249] Windows NTLM Spoofing Vulnerability

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. Affected products named by the advisory: Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); Windows Server 2016; Windows Server 2016 (Server Core installation); and 6 more. Affected products named by the advisory: Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-21249
Windows Server
Feb 10, 2026
Low3.1F5

Low [CVE-2026-20732] vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20732
BIG-IP
Feb 4, 2026
Low3.3F5

Low [CVE-2026-20730] vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2026-20730
BIG-IP
Feb 4, 2026
Low3.8Fortinet

Low [CVE-2025-67685] Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4…

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.

CVE-2025-67685
FortiSandbox
Jan 13, 2026
Low3.3QNAP

Low [CVE-2025-62840] generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync

A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later Affected product named by the advisory: HBS 3 Hybrid Backup Sync 26.1.x and earlier.

CVE-2025-62840
Backup (HBS)
Jan 2, 2026
Low1.1NETGEAR

Low [CVE-2025-12945] Improper input validation in NETGEAR Nighthawk router R7000P

An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154.

CVE-2025-12945
Unclassified
Dec 9, 2025
Low1.8Fortinet

Low [CVE-2025-54821] Trusted hosts bypass via SSH

CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00 Affected products named by the advisory: FortiSASE.

CVE-2025-54821
FortiGateFirewallFortiOS
Nov 18, 2025
Low1.8Commvault

Low Stored Cross-Site Scripting Vulnerability

Stored Cross-Site Scripting Vulnerability

Unclassified
Oct 14, 2025
Low2.5Fortinet

Low [CVE-2025-58903] Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.

CVE-2025-58903
FortiGateFirewallFortiOS
Oct 14, 2025