Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

38 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.1WatchGuard

Medium [CVE-2026-3343] WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

CVE-2026-3343
Firebox / Fireware
Mar 3, 2026
Medium6.3WatchGuard

Medium [CVE-2025-1910] WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.

CVE-2025-1910
Unclassified
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-6946] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-6946
Firebox / Fireware
Dec 4, 2025
Medium6.7WatchGuard

Medium [CVE-2025-13940] WatchGuard Firebox Boot Time System Integrity Check Bypass

An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system integrity check message in the event of a failure.

CVE-2025-13940
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13939] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.

CVE-2025-13939
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13938] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.

CVE-2025-13938
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13937] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.

CVE-2025-13937
Firebox / Fireware
Dec 4, 2025
Medium4.8WatchGuard

Medium [CVE-2025-13936] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.

CVE-2025-13936
Firebox / Fireware
Dec 4, 2025
Medium6.3WatchGuard

Medium [CVE-2024-4944 +1] WatchGuard Mobile VPN with SSL Local Privilege Escallation

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5

CVE-2024-4944CVE-2025-1549
Unclassified
Oct 29, 2025
Medium4.8WatchGuard

Medium [CVE-2025-6947] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-6947
Firebox / Fireware
Sep 15, 2025
Medium6.9WatchGuard

Medium [CVE-2025-6999] WatchGuard Firebox Authentication Portal Request Smuggling Vulnerability

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.

CVE-2025-6999
Firebox / Fireware
Sep 15, 2025
Medium4.8WatchGuard

Medium [CVE-2025-4805] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-4805
Firebox / Fireware
May 16, 2025
Medium4.8WatchGuard

Medium [CVE-2025-4804] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

CVE-2025-4804
Firebox / Fireware
May 16, 2025
Medium6.3WatchGuard

Medium [CVE-2025-2782] WatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation Directory

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. Affected product named by the advisory: SSO Terminal Services Agent.

CVE-2025-2782
Unclassified
Mar 28, 2025
Medium6.3WatchGuard

Medium [CVE-2025-2781] WatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation Directory

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.

CVE-2025-2781
Unclassified
Mar 28, 2025
Medium5.1WatchGuard

Medium [CVE-2025-0178] WatchGaurd Firebox Host Header Injection Vulnerability

An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.

CVE-2025-0178
Firebox / Fireware
Feb 14, 2025
Medium4.8WatchGuard

Medium [CVE-2025-1239] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites List

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-1239
Firebox / Fireware
Feb 14, 2025
Medium4.8WatchGuard

Medium [CVE-2025-1071] WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. Affected product named by the advisory: Fireware OS.

CVE-2025-1071
Firebox / Fireware
Feb 14, 2025