Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Juniper

Medium [CVE-2026-33801] Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS). Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation. This issue affects: - Junos OS versions 25.2 before 25.2R2;

CVE-2026-33801
JunosJunos OS Evolved
Jul 9, 2026
Medium6.5Juniper

Medium [CVE-2026-33800] Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304. - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S8,

CVE-2026-33800
JunosMX304
Jul 9, 2026
Medium4.3Juniper

Medium [CVE-2026-33799] Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP. Memory usage can be monitored using the following command: user@device> show system processes extensive | match snmpd This issue affects: - all versions before 21.2R3-S8; - from 21.4 before 21.4R3-S7; - from 22.1 before 22.1R3-S6; - from 22.3 before 22.3R3-S3; - from 23.2 before 23.2R2; - from 23.4 before 23.4R2. - all versions of 22.1-EVO, - from 22.2 before 22.2R3-S4-EVO;

CVE-2026-33799
JunosJunos OS Evolved
Jul 9, 2026
Medium5.9Juniper

Medium [CVE-2026-33794] Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX: - from 24.4R2-EVO before 24.4R2-S3-EVO; - from 25.2 before 25.2R2-EVO.

CVE-2026-33794
RoutersJunosJunos OS EvolvedMX / Routers
Jul 9, 2026
Medium4.4Juniper

Medium [CVE-2026-21901] NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS)

A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS). A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition. This issue affects: - from 22.3 before 22.3R3-S5; - from 22.4 before 22.4R3-S10; - from 23.2 before 23.2R2-S7; - from 23.4 before 23.4R2-S8. This issue does not affect Junos OS before 22.3R1.

CVE-2026-21901
JunosJunos OS Evolved
Jul 9, 2026
Medium4.3GitLab

Medium [CVE-2026-8472] GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks.

CVE-2026-8472
GitLab CE / EE
Jul 8, 2026
Medium4.3GitLab

Medium [CVE-2026-7492] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

CVE-2026-7492
GitLab CE / EEGitLab Pages
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15174] GitLab: Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15174
Unclassified
Jul 8, 2026
Medium4.7GitLab

Medium [CVE-2026-15173] GitLab: pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15173
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15172] GitLab: FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15172
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15171] GitLab: SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15171
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15170] GitLab: Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15170
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15169] GitLab: UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15169
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15166] GitLab: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15166
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15165] GitLab: TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15165
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15164] GitLab: Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15164
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15163] GitLab: Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service Affected product named by the advisory: GitLab.

CVE-2026-15163
Unclassified
Jul 8, 2026
Medium4.9GitLab

Medium [CVE-2026-11827] GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.

CVE-2026-11827
GitLab CE / EE
Jul 8, 2026
Medium5.9Vendor: LowPalo Alto

Medium [CVE-2026-0281] PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
Medium5.3Vendor: LowPalo Alto

Medium [CVE-2026-0279] PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0279
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026