Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1Fortinet Exploited CISA KEV

Critical [CVE-2026-39808] OS Command Injection through API endpoint

CVSSv3 Score: 9.1 An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-04-14 00:00:00 Affected product named by the advisory: FortiSandbox PaaS.

CVE-2026-39808
FortiSandbox
Apr 14, 2026
Critical9.1Fortinet

Critical [CVE-2026-39813] Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox

CVSSv3 Score: 9.1 A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. Revised on 2026-04-14 00:00:00

CVE-2026-39813
FortiSandbox
Apr 14, 2026
Critical9.8Juniper

Critical [CVE-2026-33784] Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible. This issue affects all versions of vLWC before 3.0.94.

CVE-2026-33784
Unclassified
Apr 9, 2026
Critical9.1Fortinet Exploited CISA KEV

Critical [CVE-2026-35616] API authentication and authorization bypass

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at: - for FortiClientEMS 7.4.5https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely. Revised on 2026-04-04 00:00:00

CVE-2026-35616
FortiClient
Apr 4, 2026
Critical9.8Cisco

Critical [CVE-2026-20160] Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20160
Unclassified
Apr 1, 2026
Critical9.8Cisco

Critical [CVE-2026-20093] Cisco Integrated Management Controller Authentication Bypass Vulnerability

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. Affected products named by the advisory: Unified Computing System (Standalone); Unified Computing System E-Series Software (UCSE); Enterprise NFV Infrastructure Software.

CVE-2026-20093
Unclassified
Apr 1, 2026
Critical9.0Ubiquiti

Critical [CVE-2019-25651] Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC…

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices. Affected products named by the advisory: UniFi UAP Firmware; UniFi UAP-AC Firmware; UniFi USW Firmware; UniFi USG Firmware.

CVE-2019-25651
UniFi Network / OS
Mar 27, 2026
Critical9.3QNAP

Critical [CVE-2026-22898] QVR Pro: missing authentication for critical function vulnerability has been reported to affect QVR Pro.

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later Affected product named by the advisory: QVR Pro 2.7.x.

CVE-2026-22898
Surveillance (QVR)
Mar 20, 2026
Critical10.0Cisco

Critical [CVE-2026-20079] Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.

CVE-2026-20079
FirewallASA / Firepower
Mar 4, 2026
Critical9.3Apache

Critical [CVE-2026-27446] Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both: - incoming Core protocol connections from untrusted sources to the broker This issue affects: Users are recommended to upgrade to Apache Artemis version 2.52.0, which fixes the issue. The issue can be mitigated by one of the following: - Use two-way SSL (i.e. certificate-based authentication) in order to force every client to present the proper SSL certificate when establishing a connection before any message protocol handshake is attempted. This will prevent unauthenticated exploitation of this vulnerability. - Implement and deploy a Core interceptor to deny all Core downstream federation connect packets. Such packets have a type of (int) -16 or (byte) 0xfffffff0. Documentation for interceptors is available

CVE-2026-27446
MessagingActiveMQ
Mar 4, 2026
Critical9.4NetApp

Critical [CVE-2025-4517] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-4517
Active IQ Unified Manager
Jul 18, 2025
CriticalCommvault Exploited CISA KEV

Critical [CVE-2025-34028] Vulnerability in Commvault Command Center Installation

Vulnerability in Commvault Command Center Installation

CVE-2025-34028
Web Server / Command Center
May 7, 2025
CriticalCommvault

Critical SQL Injection and Command Injection Advisory

SQL Injection and Command Injection Advisory

Unclassified
Sep 16, 2024
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2023-7028] Weak Password Recovery Mechanism for Forgotten Password in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVE-2023-7028
Unclassified
Jan 12, 2024
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-46604] Remote Code Execution Vulnerability in Apache ActiveMQ

Remote Code Execution Vulnerability in Apache ActiveMQ

CVE-2023-46604
Unclassified
Nov 6, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-4863] Libwebp Vulnerability

CVE.Org link: CVE-2023-4863 Save as PDF

CVE-2023-4863
Unclassified
Oct 4, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2021-4104 +4] Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

CVE-2021-4104CVE-2021-44228CVE-2021-44832+2
Unclassified
Feb 1, 2022
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2021-22205] issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVE-2021-22205
Unclassified
Apr 23, 2021