Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.2VMware

High [CVE-2026-41713] malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

CVE-2026-41713
Unclassified
May 12, 2026
High7.5VMware

High [CVE-2026-41712] Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

CVE-2026-41712
Unclassified
May 12, 2026
High7.5Zyxel

High [CVE-2026-7287] ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep, formWlAc, formPasswordSetup, formUpgradeCert, and formDelcert functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request to a vulnerable device

- * UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request to a vulnerable device.

CVE-2026-7287
Unclassified
May 12, 2026
High8.8Zyxel

High [CVE-2026-7256] ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request

- * UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request.

CVE-2026-7256
Unclassified
May 12, 2026
High7.5NetApp

High [CVE-2026-23003] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.10.210 through 5.14.21, 5.15.149 through 5.15.198, 6.13-rc1 through 6.18.6, 6.19-rc1 through 6.19-rc5, 6.6.16 through 6.6.121, 6.7.4 through 6.7.12 and 6.8-rc3 through 6.12.66 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23003
Unclassified
May 8, 2026
High7.5NetApp

High [CVE-2026-29169] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-29169
Unclassified
May 8, 2026
High7.5NetApp

High [CVE-2026-22990] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.10.247, 5.11-rc1 through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22990
ONTAP tools for VMware
May 8, 2026
High7.5NetApp

High [CVE-2026-22997] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.4-rc1 through 6.12.66, 6.13-rc1 through 6.18.6 and 6.19-rc1 through 6.19-rc5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22997
Unclassified
May 8, 2026
High7.5NetApp

High [CVE-2026-34059] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp states there is no workaround available at this time.

CVE-2026-34059
Unclassified
May 8, 2026
High7.3NetApp

High [CVE-2026-29168] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.30 through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-29168
Unclassified
May 8, 2026
High8.8NetApp

High [CVE-2026-23918] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server version 2.4.66 is susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-23918
Unclassified
May 8, 2026
High7.4Ivanti

High [CVE-2026-7821] Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

CVE-2026-7821
EPMM / MobileIron
May 7, 2026
High7.0Ivanti

High [CVE-2026-5788] Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

CVE-2026-5788
EPMM / MobileIron
May 7, 2026
High8.9Ivanti

High [CVE-2026-5787] Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

CVE-2026-5787
EPMM / MobileIronSentry
May 7, 2026
High8.8Ivanti

High [CVE-2026-5786] Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

CVE-2026-5786
EPMM / MobileIron
May 7, 2026
High7.8NetApp Exploited CISA KEV

High [CVE-2026-31431] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain Linux kernel versions are susceptible to a vulnerability referred to as Copy Fail. Attackers must have access to an unprivileged local user account to successfully exploit this vulnerability. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31431
Unclassified
May 1, 2026
High8.0SonicWall

High [CVE-2026-0204 +2] SonicOS: vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible un…

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

CVE-2026-0204CVE-2026-0205CVE-2026-0206
SonicOS Firewalls
Apr 29, 2026
High7.2Zyxel

High [CVE-2026-1460] post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVE-2026-1460
Unclassified
Apr 28, 2026
High7.0VMware

High [CVE-2026-40973] Spring Boot: local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.

CVE-2026-40973
Tanzu / Spring
Apr 28, 2026
High7.5VMware

High [CVE-2026-40972] Spring Boot: attacker on the same network as the remote application

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

CVE-2026-40972
Tanzu / Spring
Apr 28, 2026