Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5F5

High [CVE-2025-46706] When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests

When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46706
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-41430] When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41430
BIG-IP
Oct 15, 2025
High7.2Aruba

High [CVE-2025-37134] authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating…

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37134
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37132] arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8…

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

CVE-2025-37132
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
HighIvanti Exploited

High October 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Neurons for MDM. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: In addition, Ivanti has issued a Security Advisory for Ivanti Endpoint Manager, which provides mitigation options for vulnerabilities disclosed October 7, 2025. It is important for customers to know:

EPMM / MobileIronNeuronsEndpoint Manager
Oct 14, 2025
High8.8QNAP

High [CVE-2025-44014] Qsync: out-of-bounds write vulnerability has been reported to affect Qsync Central.

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44014
Applications
Oct 3, 2025
High8.8QNAP

High [CVE-2024-56804] Video Station: SQL injection vulnerability has been reported to affect Video Station.

An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.4 and later

CVE-2024-56804
Applications
Oct 3, 2025
High8.2NetApp

High [CVE-2025-55163] Apache Netty Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Netty. Apache Netty versions prior to 4.2.4.Final and prior to 4.1.124.Final are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2025-55163
Unclassified
Oct 3, 2025
High7.2Aruba

High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.

CVE-2025-37127
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVE-2025-37126
EdgeConnect SD-WAN
Sep 16, 2025
High7.5Aruba

High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-37125
EdgeConnect SD-WAN
Sep 16, 2025
High8.8Aruba

High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2025-37123
EdgeConnect SD-WAN
Sep 16, 2025
HighIvanti Exploited

High September 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. At the core, we believe that responsible transparency helps protect our customers. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager (EPM) and Ivanti Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: - Ivanti Connect Secure, Policy Secure, ZTNA and nSA

Connect Secure (VPN)Policy SecureNeuronsEndpoint Manager
Sep 9, 2025
High8.4QNAP

High [CVE-2025-44015] command injection vulnerability has been reported to affect HybridDesk Station.

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk Station 4.2.18 and later

CVE-2025-44015
Unclassified
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30278] Qsync: improper certificate validation vulnerability has been reported to affect Qsync Central.

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-30278
Applications
Aug 29, 2025
High8.1QNAP

High [CVE-2025-30273] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30273
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30264] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30264
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-29894] Qsync: SQL injection vulnerability has been reported to affect Qsync Central.

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-29894
Applications
Aug 29, 2025
High7.2QNAP

High [CVE-2025-29887] command injection vulnerability has been reported to affect QuRouter 2.5.1.

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.5.1.060 and later

CVE-2025-29887
Unclassified
Aug 29, 2025
High8.1QNAP

High [CVE-2025-47206] out-of-bounds write vulnerability has been reported to affect File Station 5.

An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later

CVE-2025-47206
Unclassified
Aug 18, 2025