Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Vendor: HighMS Server

Medium [CVE-2026-45634] Windows DHCP Client Information Disclosure Vulnerability

Windows DHCP Client Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45634
Windows Server
Jun 9, 2026
Medium5.3Vendor: HighMS Server

Medium [CVE-2026-45655] Windows BitLocker Security Feature Bypass Vulnerability

Windows BitLocker Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45655
Windows Server
Jun 9, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-50508] Windows NTLM Spoofing Vulnerability

Windows NTLM Spoofing Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server,; Windows Server 2016; Windows Server 2012; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50508
Windows Server
Jun 9, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-45454] Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-45454
SharePoint Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-45594] Windows Application Identity (AppID) Information Disclosure Vulnerability

Windows Application Identity (AppID) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-45594
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-45604] Windows Managed Installer Information Disclosure Vulnerability

Windows Managed Installer Information Disclosure Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-45604
Windows Server
Jun 9, 2026
Medium5.4Vendor: HighMS Server

Medium [CVE-2026-45595] Windows Mark of the Web Security Feature Bypass Vulnerability

Windows Mark of the Web Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45595
Windows Server
Jun 9, 2026
Medium6.8Vendor: HighMS Server PoC reported

Medium [CVE-2026-50507] Windows BitLocker Security Feature Bypass Vulnerability

Windows BitLocker Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50507
Windows Server
Jun 9, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-42903] Windows Kerberos Denial of Service Vulnerability

Windows Kerberos Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42903
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-42906] Windows Shell Information Disclosure Vulnerability

Windows Shell Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42906
Windows Server
Jun 9, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-42907] Windows Shell Information Disclosure Vulnerability

Windows Shell Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-42907
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-42915] Microsoft Windows VMSwitch Denial of Service Vulnerability

Microsoft Windows VMSwitch Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42915
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-42968] Windows Telephony Server Information Disclosure Vulnerability

Windows Telephony Server Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42968
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-42972] Windows Hyper-V Information Disclosure Vulnerability

Windows Hyper-V Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42972
Windows Server
Jun 9, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-44805] Windows Network Controller (NC) Host Agent Denial of Service Vulnerability

Windows Network Controller (NC) Host Agent Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-44805
Windows Server
Jun 9, 2026
Medium4.2VMware

Medium [CVE-2026-41854] Spring Framework: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally pro…

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

CVE-2026-41854
Tanzu / Spring
Jun 9, 2026
Medium5.3VMware

Medium [CVE-2026-41853] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41853
Tanzu / Spring
Jun 9, 2026
Medium4.7NetApp

Medium [CVE-2026-40977] Spring Boot Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Boot. Certain versions of Spring Boot are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40977
OnCommand / Data Infrastructure Insights
Jun 5, 2026
Medium6.1Cisco

Medium [CVE-2026-20233] Cisco Webex Meetings Cross-Site Scripting Vulnerability

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of insufficient validation of user input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information. There are no workarounds that address this vulnerability.

CVE-2026-20233
Unified CommunicationsWebex
Jun 3, 2026
Medium6.5Zyxel

Medium [CVE-2026-3871] buffer overflow vulnerability in the UPnP DeletePortMapping command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device

A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.

CVE-2026-3871
Unclassified
Jun 2, 2026