Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1NetApp

High [CVE-2023-43804] urllib3 Vulnerability in NetApp Products

Multiple NetApp products incorporate urllib3. Urllib3 versions prior to 1.26.17 and prior to 2.0.6 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP Mediator. NetApp states there is no workaround available at this time.

CVE-2023-43804
ONTAPElement SoftwareActive IQ Unified Manager
Dec 13, 2024
High7.5Zyxel Exploited CISA KEV

High [CVE-2024-11667] directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

CVE-2024-11667
Firewalls (USG FLEX/ATP)
Nov 27, 2024
High8.5WatchGuard

High [CVE-2024-8424] WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEM

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. Affected products named by the advisory: Endpoint Security.

CVE-2024-8424
WatchGuard Agent / EPDR
Nov 7, 2024
High8.6WatchGuard

High [CVE-2024-4944] Mobile VPN with SSL Local Privilege Escalation Vulnerability

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

CVE-2024-4944
Unclassified
Jul 9, 2024
High8.6Check Point Exploited CISA KEV

High [CVE-2024-24919] Information disclosure

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. Affected product named by the advisory: Check Point Quantum Gateway, Spark Gateway and CloudGuard Network.

CVE-2024-24919
Quantum Gateway / GaiaCloudGuard
May 28, 2024
High7.5NetApp

High [CVE-2023-24329] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Python versions prior to 3.7.17, 3.8.17, 3.9.17, 3.10.12 and 3.11.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility. NetApp states there is no workaround available at this time.

CVE-2023-24329
ONTAPElement SoftwareActive IQ Unified ManagerONTAP Select
Mar 24, 2023
High7.5Fortinet Updated

High [CVE-2022-0778] Vulnerability in OpenSSL library

CVSSv3 Score: 7.5 A security advisory was released affecting the version of OpenSSL library used in some Fortinet products:CVE-2022-0778:The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Affected products named by the advisory: FortiOS; FortiManager; FortiAnalyzer; FortiDeceptor; and 2 more.

CVE-2022-0778
FortiGateFirewallFortiOSFortiManager
Apr 1, 2022
HighCommvault Exploited CISA KEV

High [CVE-2021-4034] Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

CVE-2021-4034
Unclassified
Jan 29, 2022
High7.5NetApp Updated

High [CVE-2021-38604] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C. GNU C Library (aka glibc) versions through 2.34 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp Cloud Backup (formerly AltaVault), NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp SolidFire Baseboard Management Controller (BMC). NetApp states there is no workaround available at this time.

CVE-2021-38604
AFF / ASA / FASElement Software
Sep 9, 2021