Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

569 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Apache

Critical [CVE-2026-57308] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

CVE-2026-57308
Unclassified
Jul 20, 2026
Critical9.8Apache

Critical [CVE-2026-53421] Improper Isolation or Compartmentalization vulnerability in Apache Syncope

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.

CVE-2026-53421
Unclassified
Jul 20, 2026
Critical9.8Apache

Critical [CVE-2026-53405] Improper Isolation or Compartmentalization vulnerability in Apache Syncope

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.

CVE-2026-53405
Unclassified
Jul 20, 2026
Critical9.8Apache

Critical [CVE-2026-63071] Improper Isolation or Compartmentalization vulnerability in Apache Syncope

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.

CVE-2026-63071
Unclassified
Jul 20, 2026
Critical9.8VMware

Critical [CVE-2026-47865] Avi Load Balancer: VMware Avi Load Balancer contains an authentication bypass vulnerability.

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.

CVE-2026-47865
Avi / VeloCloud
Jul 18, 2026
Critical9.1NetApp

Critical [CVE-2026-59083] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.0.M1 through 9.0.119, and 8.5.0 through 8.5.100 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59083
Unclassified
Jul 17, 2026
Critical9.1NetApp

Critical [CVE-2026-59084] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59084
Unclassified
Jul 17, 2026
Critical9.1NetApp

Critical [CVE-2026-6100] CPython Vulnerability in NetApp Products

Certain versions of CPython are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6100
Active IQ Unified Manager
Jul 17, 2026
Critical9.6VMware

Critical [CVE-2026-22752] Spring Security: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

CVE-2026-22752
Tanzu / Spring
Jul 16, 2026
Critical9.2F5

Critical [CVE-2026-42533] vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42533
NGINX
Jul 15, 2026
Critical10.0SonicWall Exploited CISA KEV

Critical [CVE-2026-15409 +1] Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVE-2026-15409CVE-2026-15410
Unclassified
Jul 14, 2026
Critical9.3Vendor: HighMS Server

Critical [CVE-2026-49798] Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-49798
Windows Server
Jul 14, 2026
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2026-58644] Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-58644
SharePoint Server
Jul 14, 2026
Critical9.8MS Server

Critical [CVE-2026-54118] Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SQL Server 2016; Microsoft SQL Server 2019; Microsoft SQL Server 2022; Microsoft SQL Server 2017; and 1 more. Affected products named by the advisory: Microsoft SQL Server 2025.

CVE-2026-54118
SQL Server
Jul 14, 2026
Critical9.8MS Server

Critical [CVE-2026-54117] Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server Remote Code Execution Vulnerability Affected product named by the advisory: Microsoft SQL Server 2025.

CVE-2026-54117
SQL Server
Jul 14, 2026
Critical9.6MS Server

Critical [CVE-2026-55008] Microsoft Exchange Server Spoofing Vulnerability

Microsoft Exchange Server Spoofing Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 15; Microsoft Exchange Server Subscription Edition RTM.

CVE-2026-55008
Exchange Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-54990] Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-54990
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-49172] Windows FTP Service Remote Code Execution Vulnerability

Windows FTP Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2025; Windows Server 2022; Windows Server 2019.

CVE-2026-49172
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-42990] SQL Server ODBC driver Elevation of Privilege Vulnerability

SQL Server ODBC driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42990
Windows Server
Jul 14, 2026
Critical9.8Apache

Critical [CVE-2026-62392] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

CVE-2026-62392
Unclassified
Jul 14, 2026