Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3NetApp

Medium [CVE-2026-22007 +2] July 2026 IBM Db2 IBM Semeru Vulnerabilities in NetApp Products

IBM Db2 Client and Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are susceptible to vulnerabilities in IBM Semeru 21.0.10.0 and earlier. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-22007CVE-2026-22013CVE-2026-22021
Unclassified
Jul 17, 2026
Medium5.3NetApp

Medium [CVE-2026-27448] pyOpenSSL Vulnerability in NetApp Products

pyOpenSSL versions 0.14 prior to 26.0.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: NetApp Data Classification. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27448
Unclassified
Jul 17, 2026
Medium5.4Apache

Medium [CVE-2026-26032] The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by…

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains "../" sequences - which are valid characters for Ivy coordinates in general- it is possible to break out of the configured "buildRoot" directory where other files can be overwritten. In order to exploit this vulnerability an attacker needs to have access to a packager repository and add or modify the coordinates in ivy.xml files to have such "../" sequences. Users of Apache Ivy 2.0.0 to 2.5.3 (inclusive) should upgrade to Ivy 2.6.0.

CVE-2026-26032
Unclassified
Jul 15, 2026
Medium5.5Cisco

Medium [CVE-2026-20146] Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected products named by the advisory: Identity Services Engine Software.

CVE-2026-20146
ISEIdentity Services Engine
Jul 15, 2026
Medium6.3F5

Medium [CVE-2026-60065] When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-60065
NGINX
Jul 15, 2026
Medium5.3F5

Medium [CVE-2026-60062] The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-60062
NGINX
Jul 15, 2026
Medium4.3NETGEAR

Medium [CVE-2026-62659] security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings

A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings

CVE-2026-62659
Unclassified
Jul 14, 2026
Medium4.7NETGEAR

Medium [CVE-2026-62658] security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router

A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router. Affected products named by the advisory: RAX43; RAX45; RAX50; RAX54S; and 1 more. Affected products named by the advisory: RAX54Sv2.

CVE-2026-62658
Unclassified
Jul 14, 2026
Medium4.9NETGEAR

Medium [CVE-2026-62657] security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device

A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device. Affected products named by the advisory: MR70; MS70; RAXE500.

CVE-2026-62657
Unclassified
Jul 14, 2026
Medium5.4NETGEAR

Medium [CVE-2026-62656] security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands

A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation. Affected products named by the advisory: RAXE450; RAXE500.

CVE-2026-62656
Unclassified
Jul 14, 2026
Medium5.7NETGEAR

Medium [CVE-2026-62655] security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable

A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable. Affected products named by the advisory: RBR860; RBRE950; RBRE960; RBE970; and 4 more. Affected products named by the advisory: RBE971; RBS860; RBSE950; RBSE960.

CVE-2026-62655
Unclassified
Jul 14, 2026
Medium6.3NETGEAR

Medium [CVE-2026-15757] security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device

A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.

CVE-2026-15757
Unclassified
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50303] Windows Key Guard Security Feature Bypass Vulnerability

Windows Key Guard Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-50303
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50300] Windows DWM Core Library Information Disclosure Vulnerability

Windows DWM Core Library Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50300
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50381] Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability

Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-50381
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50350] Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability

Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-50350
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50295] Windows Zero Trust DNS Security Feature Bypass Vulnerability

Windows Zero Trust DNS Security Feature Bypass Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-50295
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50316] Windows Kernel Information Disclosure Vulnerability

Windows Kernel Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-50316
Windows Server
Jul 14, 2026
Medium6.8Vendor: HighMS Server

Medium [CVE-2026-50298] Windows Spaceport.sys Elevation of Privilege Vulnerability

Windows Spaceport.sys Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50298
Windows Server
Jul 14, 2026
Medium6.2Vendor: HighMS Server

Medium [CVE-2026-49807] Windows DirectX Information Disclosure Vulnerability

Windows DirectX Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-49807
Windows Server
Jul 14, 2026