Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.1Apache

Medium [CVE-2026-66390] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

CVE-2026-66390
Unclassified
Jul 27, 2026
Medium5.9Apache

Medium [CVE-2026-41603 +1] Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

CVE-2026-41603CVE-2026-66053
Unclassified
Jul 27, 2026
Medium6.9Apache

Medium [CVE-2026-58023] Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-58023
Unclassified
Jul 27, 2026
Medium6.9Apache

Medium [CVE-2026-55970] Buffer Over-read vulnerability in Apache Thrift C++ bindings

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-55970
Unclassified
Jul 27, 2026
Medium6.9Apache

Medium [CVE-2026-45112] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-45112
Unclassified
Jul 27, 2026
Medium6.5Apache

Medium [CVE-2026-49326] Missing Authorization vulnerability in Apache HBase thrift and rest delegation service

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users. This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.

CVE-2026-49326
Big Data
Jul 24, 2026
Medium5.3Apache

Medium [CVE-2026-46452] Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CVE-2026-46452
Unclassified
Jul 24, 2026
Medium6.5Apache

Medium [CVE-2026-45812] Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application. Severity is low: NimBLE's own controller never batches multiple reports into one event, so this only matters when NimBLE's host is paired with a third-party controller that does. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CVE-2026-45812
Unclassified
Jul 24, 2026
Medium5.6Apache

Medium [CVE-2026-63317] Apache OpenNLP: Arbitrary Class Instantiation

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke its no-arg constructor without any prior validation of the class name or its type. The affected paths are: (1) GeneratorFactory, which reads the class attribute of generator elements in an XML feature generator descriptor; such descriptors are embedded as artifacts in model archives (e.g. TokenNameFinder and POSTagger models) and are parsed during model loading, so an attacker who can supply a crafted model archive controls the class name directly. (2) StreamFactoryRegistry.getFactory(Class, String), which falls back to interpreting an unregistered format name as the fully-qualified class name of an ObjectStreamFactory; this is exploitable in applications that pass untrusted format names (e.g. exposing the -format parameter of the command-line tooling to external input). (3) StringInterners, which instantiates the interner implementation named by the opennlp.interner.class system property; this value is normally deployer-controlled, so it is hardened as defense in depth rather than being independently attacker-reachable.

CVE-2026-63317
Unclassified
Jul 24, 2026
Medium6.3NetApp

Medium [CVE-2026-49844] Apache Log4j Vulnerability in NetApp Products

Apache Log4j versions 2.13.1 through 2.25.4 and version 2.26.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49844
Unclassified
Jul 24, 2026
Medium6.7NetApp

Medium [CVE-2026-60526] Java Platform Standard Edition Vulnerability in NetApp Products

Java SE versions 8u491 and 8u491-perf are susceptible to a vulnerability which when successfully exploited could allow a low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2026” for additional details. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-60526
Unclassified
Jul 24, 2026
Medium5.3NetApp

Medium [CVE-2026-47013 +5] July 2026 Java Platform Standard Edition 8u491 Vulnerabilities in NetApp Products

Java SE version 8u491 is susceptible to vulnerabilities that could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2026” for additional details. Successful attacks of these vulnerabilities can result in the unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, unauthorized update, insert or delete access to some of Oracle Java SE accessible data or unauthorized read access to a subset of Oracle Java SE accessible data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-47013CVE-2026-47030CVE-2026-47034+3
Unclassified
Jul 24, 2026
Medium5.3NetApp

Medium [CVE-2026-46917] Java Platform Standard Edition Vulnerability in NetApp Products

Java SE versions 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - July 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-46917
Active IQ Unified Manager
Jul 24, 2026
Medium5.4NetApp

Medium [CVE-2026-15995] IBM Cognos Analytics Vulnerability in NetApp Products

The IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant used by authorized analysts to query report summaries and perform related tasks. Refer to the vendor advisory for additional information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-15995
Unclassified
Jul 24, 2026
Medium6.0Docker

Medium [CVE-2026-15792] malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

CVE-2026-15792
BuildKit / Compose
Jul 21, 2026
Medium6.9Docker

Medium [CVE-2026-15789] custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

CVE-2026-15789
BuildKit / Compose
Jul 21, 2026
Medium5.4Apache

Medium [CVE-2026-58624] Improper input validation in sshd-git in Apache MINA SSHD

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. This GitPgmCommandFactory allowed a user authenticated via SSH to run any JGit command available, including commands that could write files at arbitrary places such as git archive with the --output option. Affected are SSH servers implemented with Apache MINA SSHD and using the GitPgmCommandFactory. If the GitPgmCommandFactory is not configured on the server, the server is not affected. It is recommended to upgrade affected servers to Apache MINA SSHD 2.19.0 or 3.0.0-M5, which fix this issue. The issue is fixed by restricting the available commands to a small whitelist of uncritical commands (such as git log). git archive is also allowed, but its --output argument is ignored and the archive is always sent through the SSH channel to the client.

CVE-2026-58624
Unclassified
Jul 20, 2026
Medium5.6Docker

Medium [CVE-2026-15788] BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

CVE-2026-15788
BuildKit / Compose
Jul 20, 2026
Medium6.5Proxmox

Medium [CVE-2026-51083] Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.

CVE-2026-51083
Virtual Environment (VE)
Jul 17, 2026
Medium6.1Proxmox

Medium [CVE-2026-51081] cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

CVE-2026-51081
Virtual Environment (VE)
Jul 17, 2026