Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.4VMware

Medium [CVE-2026-40995] Spring Security: X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate map…

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts).

CVE-2026-40995
Tanzu / Spring
Jun 11, 2026
Medium5.0VMware

Medium [CVE-2026-40992] Spring Boot: Spring Boot's Mail auto-configuration does not enable hostname verification.

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected.

CVE-2026-40992
Tanzu / Spring
Jun 11, 2026
Medium4.8VMware

Medium [CVE-2026-40986] Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

CVE-2026-40986
Unclassified
Jun 11, 2026
Medium6.4VMware

Medium [CVE-2026-40985] Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

CVE-2026-40985
Unclassified
Jun 11, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0269] PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0267] GlobalProtect App: Information Exposure Vulnerability on macOS

CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS

CVE-2026-0267
GlobalProtect
Jun 10, 2026
Medium4.8Vendor: LowPalo Alto

Medium [CVE-2026-0266] PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0266
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0268] Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268
Prisma Access
Jun 10, 2026
Medium5.1QNAP

Medium [CVE-2025-62850] QuTS hero: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

CVE-2025-62850
QuTS hero
Jun 10, 2026
Medium5.1QNAP

Medium [CVE-2025-58468] cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center.

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later Affected product named by the advisory: Notification Center 1.10.x.

CVE-2025-58468
Unclassified
Jun 10, 2026
Medium6.8VMware

Medium [CVE-2026-47838] Spring Security: SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can le…

SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected product named by the advisory: Spring Security.

CVE-2026-47838
Tanzu / Spring
Jun 10, 2026
Medium5.3VMware

Medium [CVE-2026-41837] Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does…

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.

CVE-2026-41837
Unclassified
Jun 10, 2026
Medium5.3VMware

Medium [CVE-2026-41730] Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing…

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.

CVE-2026-41730
Unclassified
Jun 10, 2026
Medium6.5VMware

Medium [CVE-2026-41727] Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVE-2026-41727
Unclassified
Jun 10, 2026
Medium6.5VMware

Medium [CVE-2026-41726] When an application opts into DelegatingDeserializer, a producer

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVE-2026-41726
Unclassified
Jun 10, 2026
Medium5.9VMware

Medium [CVE-2026-41721] Spring Data Commons contains a vulnerability that can

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the application to allocate lots of memory. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

CVE-2026-41721
Unclassified
Jun 10, 2026
Medium6.4VMware

Medium [CVE-2026-41719] SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository…

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

CVE-2026-41719
Unclassified
Jun 10, 2026
Medium4.0VMware

Medium [CVE-2026-41714] Applications that configure their broker connection

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

CVE-2026-41714
Unclassified
Jun 10, 2026
Medium5.9VMware

Medium [CVE-2026-41711] Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

CVE-2026-41711
Unclassified
Jun 10, 2026
Medium6.1VMware

Medium [CVE-2026-41706] Spring Security: Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a brows…

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41706
Tanzu / Spring
Jun 10, 2026