Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

240 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low2.6Fortinet

Low [CVE-2025-31514] Insertion of Sensitive 2FA Information in logs and debug command

CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00 Affected products named by the advisory: FortiProxy.

CVE-2025-31514
FortiGateFirewallFortiOSFortiProxy
Oct 14, 2025
Low3.7F5

Low [CVE-2025-53859] NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53859
NGINX
Aug 13, 2025
Low3.9Fortinet

Low [CVE-2025-25250] Information Disclosure on SSLVPN endpoint

CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL. Revised on 2026-06-15 00:00:00 Affected products named by the advisory: FortiSASE.

CVE-2025-25250
FortiGateFirewallFortiOS
Jun 10, 2025
Low3.5Check Point

Low [CVE-2024-52887] Authenticated end-user may set a specially crafted SNX bookmark

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

CVE-2024-52887
Unclassified
Apr 27, 2025
Low2.1Fortinet

Low [CVE-2024-32122] storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all…

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.

CVE-2024-32122
FortiGateFirewallFortiOS
Apr 8, 2025
Low3.3Aruba

Low [CVE-2025-25040] vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300…

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx: All patches - AOS-CX 10.15.xxxx: 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.

CVE-2025-25040
AOS-CXSwitches (AOS-CX)
Mar 18, 2025
Low3.1F5

Low [CVE-2025-23415] insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-23415
BIG-IP
Feb 5, 2025
Low3.5Fortinet

Low [CVE-2024-52963] out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0…

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. Affected products named by the advisory: FortiProxy.

CVE-2024-52963
FortiGateFirewallFortiOS
Jan 14, 2025
Low3.1Splunk

Low [CVE-2024-53245] In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a…

In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard.

CVE-2024-53245
Splunk EnterpriseSplunk Cloud Platform
Dec 10, 2024
Low2.6QNAP

Low [CVE-2024-32771] QTS: improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating…

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QTS 5.2.0.2782 build 20240601 and later Affected products named by the advisory: QuTS hero.

CVE-2024-32771
QTSQuTS hero
Sep 6, 2024
Low3.5QNAP

Low [CVE-2024-27125] Helpdesk: cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk.

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later

CVE-2024-27125
Unclassified
Sep 6, 2024
Low3.7Aruba

Low [CVE-2024-25616] Aruba has identified certain configurations of ArubaOS that can

Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

CVE-2024-25616
AOS-8 MobilityWireless & ControllersArubaOS
Mar 5, 2024
Low3.7GitLab

Low [CVE-2023-3509] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVE-2023-3509
Unclassified
Feb 21, 2024
Low3.8F5

Low [CVE-2024-23603] BIG-IP: An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23603
BIG-IP
Feb 14, 2024
Low3.4QNAP

Low [CVE-2023-50359] QTS: unchecked return value vulnerability has been reported to affect several QNAP operating system versions.

An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated administrators to place the system in a state that could lead to a crash or other unintended behaviors via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later

CVE-2023-50359
QTSQuTS hero
Feb 2, 2024
Low3.8QNAP

Low [CVE-2023-45037] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2023-45037
QTSQuTS hero
Feb 2, 2024
Low3.8QNAP

Low [CVE-2023-45035] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2023-45035
QTSQuTS hero
Feb 2, 2024
Low3.5QNAP

Low [CVE-2023-47219] QuMagie: SQL injection vulnerability has been reported to affect QuMagie.

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVE-2023-47219
Applications
Jan 5, 2024
Low3.8QNAP

Low [CVE-2023-45044] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later Affected products named by the advisory: QuTS hero.

CVE-2023-45044
QTSQuTS hero
Jan 5, 2024
Low3.1GitLab

Low [CVE-2023-3443] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVE-2023-3443
Unclassified
Dec 1, 2023