Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Vendor: HighMS Server

Medium [CVE-2026-34346] Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-34346
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-34349] Windows Media Information Disclosure Vulnerability

Windows Media Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-34349
Windows Server
Jul 14, 2026
Medium6.5Apache

Medium [CVE-2026-49488] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.

CVE-2026-49488
Unclassified
Jul 14, 2026
Medium4.3Apache

Medium [CVE-2026-62393] Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

CVE-2026-62393
Unclassified
Jul 14, 2026
Medium5.9Fortinet

Medium [CVE-2026-59837] Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00

CVE-2026-59837
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Medium4.1Fortinet

Medium [CVE-2025-43892 +1] Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

CVE-2025-43892CVE-2026-59840
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Medium5.3Fortinet

Medium [CVE-2026-59838] Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

CVE-2026-59838
FortiSIEM
Jul 14, 2026
Medium6.7Fortinet

Medium [CVE-2026-59836] Missed certificate verification in AD Connector communication with FortiClient EMS

CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00

CVE-2026-59836
Unclassified
Jul 14, 2026
Medium5.0Fortinet

Medium [CVE-2026-59839] Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

CVE-2026-59839
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Medium6.1Fortinet

Medium [CVE-2026-23573] SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00

CVE-2026-23573
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Medium6.9Fortinet

Medium [CVE-2026-59841] Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00

CVE-2026-59841
FortiSIEM
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-49177] Windows TCP/IP Information Disclosure Vulnerability

Windows TCP/IP Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-49177
Windows Server
Jul 14, 2026
Medium4.2Vendor: HighMS Server

Medium [CVE-2026-50302] Windows Cryptographic Services Security Feature Bypass Vulnerability

Windows Cryptographic Services Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-50302
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50434] Windows Push Notification Information Disclosure Vulnerability

Windows Push Notification Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-50434
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50339] Windows Push Notification Information Disclosure Vulnerability

Windows Push Notification Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-50339
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50430] Windows Push Notification Information Disclosure Vulnerability

Windows Push Notification Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50430
Windows Server
Jul 14, 2026
Medium4.7Vendor: HighMS Server

Medium [CVE-2026-50310] Windows Human Interface Device Information Disclosure Vulnerability

Windows Human Interface Device Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-50310
Windows Server
Jul 14, 2026
Medium5.9Vendor: HighMS Server

Medium [CVE-2026-50324] Windows Active Directory Federation Services Denial of Service Vulnerability

Windows Active Directory Federation Services Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 4 more. Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012 R2.

CVE-2026-50324
Windows Server
Jul 14, 2026
Medium4.7Vendor: HighMS Server

Medium [CVE-2026-50312] Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50312
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50377] Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50377
Windows Server
Jul 14, 2026