Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.4VMware

Medium [CVE-2026-41701] Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

CVE-2026-41701
Unclassified
Jun 10, 2026
Medium4.8VMware

Medium [CVE-2026-41697] Spring Data Relational does not properly escape binding values of externally-controlled input

Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected versions: Spring Data Relational/JDBC/R2DBC 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.4.0 through 2.4.19.

CVE-2026-41697
Unclassified
Jun 10, 2026
Medium5.9VMware

Medium [CVE-2026-41696] Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient…

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.

CVE-2026-41696
Unclassified
Jun 10, 2026
Medium6.1VMware

Medium [CVE-2026-41008] Spring Security: Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri par…

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected versions: Spring Security 7.0.0 through 7.0.5.

CVE-2026-41008
Tanzu / Spring
Jun 10, 2026
Medium5.9VMware

Medium [CVE-2026-40991] When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker…

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions: Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE.

CVE-2026-40991
Unclassified
Jun 10, 2026
Medium5.6NETGEAR

Medium [CVE-2026-9212] Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

CVE-2026-9212
Unclassified
Jun 9, 2026
Medium4.9NETGEAR

Medium [CVE-2026-9210] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

CVE-2026-9210
Unclassified
Jun 9, 2026
Medium4.6NETGEAR

Medium [CVE-2026-0420] improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

CVE-2026-0420
Unclassified
Jun 9, 2026
Medium4.4NETGEAR

Medium [CVE-2026-0419] Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018, and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.

CVE-2026-0419
Unclassified
Jun 9, 2026
Medium4.3NETGEAR

Medium [CVE-2026-0417] Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

CVE-2026-0417
Unclassified
Jun 9, 2026
Medium4.3NETGEAR

Medium [CVE-2026-0416] insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality

An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.

CVE-2026-0416
Unclassified
Jun 9, 2026
Medium4.3NETGEAR

Medium [CVE-2026-0413] buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality

A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

CVE-2026-0413
Unclassified
Jun 9, 2026
Medium4.3NETGEAR

Medium [CVE-2026-0412] Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.

CVE-2026-0412
Unclassified
Jun 9, 2026
Medium4.2NETGEAR

Medium [CVE-2026-0411] information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.

CVE-2026-0411
Orbi (Mesh WiFi)
Jun 9, 2026
Medium4.8NETGEAR

Medium [CVE-2026-0409] Orbi: NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions

A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.

CVE-2026-0409
Orbi (Mesh WiFi)
Jun 9, 2026
Medium5.6GitLab

Medium [CVE-2026-6899] GitLab: Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the…

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. Affected product named by the advisory: GitLab.

CVE-2026-6899
Unclassified
Jun 9, 2026
Medium6.2Fortinet

Medium [CVE-2026-49938] Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00

CVE-2026-49938
Unclassified
Jun 9, 2026
Medium6.0Fortinet

Medium [CVE-2025-67862] Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

CVE-2025-67862
FortiGateFirewallFortiOSFortiProxy
Jun 9, 2026
Medium6.1Vendor: HighMS Server

Medium [CVE-2026-45500] Microsoft Exchange Server Spoofing Vulnerability

Microsoft Exchange Server Spoofing Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Exchange Server Subscription Edition RTM; Microsoft Exchange Server 2019 Cumulative Update 15; Microsoft Exchange Server 2016 Cumulative Update 23.

CVE-2026-45500
Exchange Server
Jun 9, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-45501] Microsoft Exchange Server Spoofing Vulnerability

Microsoft Exchange Server Spoofing Vulnerability Affected products named by the advisory: Microsoft Exchange Server Subscription Edition RTM; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 15; Microsoft Exchange Server 2019 Cumulative Update 14.

CVE-2026-45501
Exchange Server
Jun 9, 2026