Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.3GitLab

Medium [CVE-2026-8716] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

CVE-2026-8716
GitLab CE / EE
May 27, 2026
Medium5.3GitLab

Medium [CVE-2026-6713] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.

CVE-2026-6713
GitLab CE / EE
May 27, 2026
Medium6.2Synology

Medium [CVE-2026-2237] use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. Affected products named by the advisory: Storage Manager for DSM 7.3; Storage Manager for DSM 7.2.2; Storage Manager for DSM 7.2.1.

CVE-2026-2237
DSM (DiskStation Manager)
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-66593] origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

Synology has released a security update for the Assistant on Windows to address a vulnerability: CVE-2025-66593 allows local users to write arbitrary files with restricted content. Please refer to the ' Affected product named by the advisory: Synology Assistant.

CVE-2025-66593
Unclassified
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-66592] origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

Synology has released a security update for the Active Backup for Business Agent on Windows to address a vulnerability: CVE-2025-66592 allows local users to write arbitrary files with restricted content. Please refer to the ' Affected product named by the advisory: Synology Active Backup for Business Agent.

CVE-2025-66592
Applications
May 27, 2026
Medium6.1Synology

Medium [CVE-2025-13593] Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation

Synology has released a security update for the ActiveProtect Agent on Windows to address a vulnerability: CVE-2025-13593 allows local users to write arbitrary files with restricted content. Please refer to the '

CVE-2025-13593
Unclassified
May 27, 2026
Medium5.4Synology

Medium [CVE-2025-13167] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. Affected products named by the advisory: Synology Contacts for DSM 7.3; Synology Contacts for DSM 7.2.2; Synology Contacts for DSM 7.2.1.

CVE-2025-13167
DSM (DiskStation Manager)
May 27, 2026
Medium5.9Synology

Medium [CVE-2025-10466] Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. Affected product named by the advisory: Safe Access for SRM 1.3.

CVE-2025-10466
SRM (Router Manager)
May 27, 2026
Medium4.9Synology

Medium [CVE-2024-47267 +5] Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. Affected products named by the advisory: Surveillance Station for DSM 7.2; Surveillance Station for DSM 7.1; Surveillance Station for DSM 6.2.

CVE-2024-47267CVE-2024-47268CVE-2024-47269+3
DSM (DiskStation Manager)Applications
May 27, 2026
Medium4.1Check Point

Medium [CVE-2026-48136] When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).The issue affects: R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below This issue received the ID CVE-2026-48136. Affected products named by the advisory: Multi-Domain Security Management Server.

CVE-2026-48136
Security Management
May 26, 2026
Medium5.3Check Point

Medium [CVE-2026-48135] Check Point HTTP-based service can incorrectly handle malformed HTTP requests

A Check Point HTTP-based service, such as Mobile Access Portal or Identity Awareness Portals (except for Captive Portal), can incorrectly handle malformed HTTP requests. Gaia Portal is not affected by this issue. The issue is related to HTTP request parsing and validation. The attacker can exploit this vulnerability leading to Denial of Service, HTTP header injection, or heap buffer overflow. This issue affects: R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below This issue received the ID CVE-2026-48135. Affected products named by the advisory: Security Gateway; Spark Firewall (Locally Managed).

CVE-2026-48135
Quantum Gateway / Gaia
May 26, 2026
Medium5.6Check Point

Medium [CVE-2026-48134] Check Point: When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow.

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks. Affected product named by the advisory: Check Point.

CVE-2026-48134
Quantum Gateway / Gaia
May 26, 2026
Medium6.5Zyxel

Medium [CVE-2026-4795] missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.

CVE-2026-4795
Switches (GS-series)
May 26, 2026
Medium6.8Cisco

Medium [CVE-2026-20171] Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. Affected products named by the advisory: NX-OS Software.

CVE-2026-20171
SwitchesNexusNX-OSNexus 3000
May 20, 2026
Medium4.7Cisco

Medium [CVE-2026-20199] Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: ThousandEyes Enterprise Agent.

CVE-2026-20199
Unclassified
May 20, 2026
Medium6.3Cisco

Medium [CVE-2026-20206] Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by authenticating to the ThousandEyes SaaS and submitting crafted input into the affected parameter. A successful exploit could have allowed the attacker to execute arbitrary commands within the BrowserBot container as the node user. To exploit this vulnerability, the attacker must have valid user credentials for the ThousandEyes SaaS and the ability to manage transaction tests. There are no workarounds that address this vulnerability.

CVE-2026-20206
Unclassified
May 20, 2026
Medium5.3NetApp

Medium [CVE-2026-7009] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 8.17.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-7009
AFF / ASA / FASElement Software
May 15, 2026
Medium5.3NetApp

Medium [CVE-2026-7168] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.12.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-7168
AFF / ASA / FASElement Software
May 15, 2026
Medium6.5NetApp

Medium [CVE-2026-5545] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.10.6 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5545
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 15, 2026
Medium5.9NetApp

Medium [CVE-2026-6253] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.14.1 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6253
AFF / ASA / FASElement Software
May 15, 2026