Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.6VMware

High [CVE-2026-41003] Spring Security: attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms gene…

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41003
Tanzu / Spring
Jun 10, 2026
High7.3VMware

High [CVE-2026-40993] Spring Security: attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asser…

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively). Affected versions: Spring Security 7.0.0 through 7.0.5.

CVE-2026-40993
Tanzu / Spring
Jun 10, 2026
High7.5VMware

High [CVE-2026-40988] Spring Security: application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may…

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-40988
Tanzu / Spring
Jun 10, 2026
High8.7NetApp

High [CVE-2026-49975] Apache HTTP Server Vulnerability in NetApp Products

The default HTTP/2 protocol configuration in certain web servers, such as Apache HTTP Server, allows a remote Denial of Service (DoS). This vulnerability is known as HTTP/2 Bomb. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49975
Element Software
Jun 10, 2026
High7.8Omnissa

High [CVE-2026-22926] Omnissa Workspace ONE Assist for macOS contains a Local Privilege Escalation Vulnerability.

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

CVE-2026-22926
Workspace ONE Apps (Hub/Tunnel/Assist)
Jun 9, 2026
HighIvanti Exploited

High June 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry. It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories:

EPMM / MobileIronEndpoint ManagerSentry
Jun 9, 2026
High8.1VMware

High [CVE-2026-41855] Spring Framework: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sp…

In an untrusted JMS environment, org.springframework.jms.support.converter. MappingJackson2MessageConverter and org.springframework.jms.support.converter. JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41855
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41850] Spring Framework: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected product named by the advisory: Spring Framework.

CVE-2026-41850
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41849] Spring Framework: integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL).

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected product named by the advisory: Spring Framework.

CVE-2026-41849
Tanzu / Spring
Jun 9, 2026
High7.1VMware

High [CVE-2026-41845] Spring Framework: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected product named by the advisory: Spring Framework.

CVE-2026-41845
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41842] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected product named by the advisory: Spring Framework.

CVE-2026-41842
Tanzu / Spring
Jun 9, 2026
High7.4VMware

High [CVE-2026-41720] Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired…

Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.

CVE-2026-41720
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-41007] Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

CVE-2026-41007
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-41006] Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type…

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.

CVE-2026-41006
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-40983] In Micrometer, it is possible for a user to provide specially crafted gRPC requests

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.

CVE-2026-40983
Unclassified
Jun 9, 2026
High7.4Check Point

High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.

CVE-2026-50752
Unclassified
Jun 8, 2026
High8.0VMware

High [CVE-2026-41724] VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with…

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

CVE-2026-41724
Cloud Foundation
Jun 8, 2026
High7.5NetApp

High [CVE-2026-40972 +3] April 2026 Spring Boot Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Spring Boot. Spring Boot versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.3.0 through 3.3.18, and 2.7.0 through 2.7.32 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). OnCommand Insight: Affected only by CVE-2026-40975. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40972CVE-2026-40973CVE-2026-40974+1
OnCommand / Data Infrastructure Insights
Jun 5, 2026
High8.7NetApp

High [CVE-2026-35554] Apache Kafka Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Kafka. Apache Kafka versions 2.8.0 through 3.9.1, 4.0.0 through 4.0.1, and 4.1.0 through 4.1.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-35554
Unclassified
Jun 5, 2026
High8.1NetApp

High [CVE-2026-9256] NGINX Vulnerability in NetApp Products

Multiple NetApp products incorporate NGINX. NGINX versions prior to 1.30.2 and 1.31.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-9256
Unclassified
Jun 5, 2026