Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5VMware

High [CVE-2026-22754] ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules

Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVE-2026-22754
Tanzu / Spring
Apr 22, 2026
High7.5VMware

High [CVE-2026-22753] Spring Security: Vulnerability in Spring Spring Security.

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher. Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVE-2026-22753
Tanzu / Spring
Apr 22, 2026
High8.2NetApp

High [CVE-2026-24842] Node-tar Vulnerability in NetApp Products

Multiple NetApp products incorporate node-tar. Node-tar versions prior to 7.5.7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-24842
Unclassified
Apr 22, 2026
High7.5Apache

High [CVE-2026-32228] UI / API User with asset materialize permission could trigger dags they had no access to.

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

CVE-2026-32228
Airflow
Apr 18, 2026
High8.8Apache

High [CVE-2026-30898] example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice.

CVE-2026-30898
Airflow
Apr 18, 2026
High8.6VMware

High [CVE-2026-22734] Cloud Foundry UUA is vulnerable to a bypass

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This issue affects UUA from v77.30.0 to v78.7.0 (inclusive) and it affects CF Deployment from v48.7.0 to v54.14.0 (inclusive).

CVE-2026-22734
Unclassified
Apr 17, 2026
High8.8NetApp

High [CVE-2026-23950] Node-Tar Vulnerability in NetApp Products

Multiple NetApp products incorporate Node-Tar. Node-Tar versions through 7.5.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23950
AFF / ASA / FASElement Software
Apr 17, 2026
High8.8NetApp Exploited CISA KEV

High [CVE-2026-34197] Apache ActiveMQ Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache ActiveMQ. Apache ActiveMQ versions prior to 5.19.4 and 6.0.0 prior to 6.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-34197
Unclassified
Apr 17, 2026
High7.5NetApp

High [CVE-2026-32597] PyJWT Vulnerability in NetApp Products

Multiple NetApp products incorporate PyJWT. PyJWT versions prior to 2.12.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-32597
Unclassified
Apr 17, 2026
HighIvanti Exploited

High April 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Neurons for ITSM (on-premises and cloud). It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. - Customers using the cloud version of Ivanti Neurons for ITSM do not need to take any action as the fix was applied on 12 December 2025 to all cloud environments.

Neurons
Apr 14, 2026
High8.1NetApp

High [CVE-2026-33938] Handlebars.js Vulnerability in NetApp Products

Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-33938
Unclassified
Apr 10, 2026
High7.0NetApp

High [CVE-2026-4519] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-4519
Active IQ Unified Manager
Apr 10, 2026
High7.5NetApp

High [CVE-2026-33939] Handlebars.js Vulnerability in NetApp Products

Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-33939
Unclassified
Apr 10, 2026
High7.5NetApp

High [CVE-2026-21710] Node.js Vulnerability in NetApp Products

Multiple NetApp products incorporate Node.js. All Node.js HTTP servers on 20.x, 22.x, 24.x, and 25.x are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-21710
Unclassified
Apr 10, 2026
High7.4Juniper

High [CVE-2026-33771] Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2. Affected product named by the advisory: EX. Affected product named by the advisory: EX.

CVE-2026-33771
SwitchesEX / QFX Switches
Apr 9, 2026
High7.2SonicWall

High [CVE-2026-4112 +3] Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances all…

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. Affected product named by the advisory: SSL VPN.

CVE-2026-4112CVE-2026-4113CVE-2026-4114+1
SSL-VPN & Clients
Apr 9, 2026
High7.5NetApp

High [CVE-2026-1519] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, and 9.21.0 through 9.21.19 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-1519
Unclassified
Apr 3, 2026
HighNetScaler Exploited CISA KEV

High [CVE-2026-3055] Important Update: CVE Disclosures Now Live on the Citrix Community Site

All CVE disclosure blogs have moved to The Citrix Community Site Going forward, all CVE disclosure blogs will be published in the Security Updates tab on the Citrix Community website. CVE-2026-3055 & CVE 2026-4368 Cloud Software Group released builds on March 23, 2026 to address CVE-2026-3055 and CVE 2026-4368.

CVE-2026-3055
Unclassified
Mar 27, 2026
High8.2VMware

High [CVE-2026-22733] Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

CVE-2026-22733
Tanzu / Spring
Mar 20, 2026
High8.8VMware

High [CVE-2026-22730] critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.

CVE-2026-22730
Unclassified
Mar 18, 2026