Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1QNAP

High [CVE-2025-22482] Qsync: use of externally-controlled format string vulnerability has been reported to affect Qsync Central.

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVE-2025-22482
Applications
Jun 6, 2025
High8.8QNAP

High [CVE-2025-22481] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.

CVE-2025-22481
QTSQuTS hero
Jun 6, 2025
High7.8QNAP

High [CVE-2024-13088] improper authentication vulnerability has been reported to affect QHora.

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later

CVE-2024-13088
Unclassified
Jun 6, 2025
High8.8Atlassian

High [CVE-2025-22157] Jira Service Management: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0…

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 See the release notes. This vulnerability was reported via our Atlassian (Internal) program. Affected product named by the advisory: Jira Service Management.

CVE-2025-22157
Jira
May 20, 2025
HighIvanti Exploited

High May Security Update

Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, Ivanti is disclosing vulnerabilities in Ivanti ITSM (on-premises only), Cloud Security Application (CSA) and Neurons for MDM. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste into your preferred RSS reader / functionality in your email program.

Neurons
May 13, 2025
High8.8F5

High [CVE-2025-46265] On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+)

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46265
F5OS / Distributed Cloud
May 7, 2025
High7.5F5

High [CVE-2025-41433] When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured…

When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41433
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-41431] BIG-IP: When connection mirroring is configured on a virtual server, undisclosed requests

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41431
BIG-IP
May 7, 2025
High7.5F5

High [CVE-2025-41414] When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate

When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2025-41414
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-41399] When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41399
Unclassified
May 7, 2025
High7.5F5

High [CVE-2025-36557] When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests

When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36557
Unclassified
May 7, 2025
High8.1F5

High [CVE-2025-36546] On an F5OS system, if the root user had previously configured the system to allow login

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the root user's SSH private key. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36546
F5OS / Distributed Cloud
May 7, 2025
High7.5F5

High [CVE-2025-36525] When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate

When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36525
BIG-IP
May 7, 2025
High7.5F5

High [CVE-2025-36504] When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses

When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36504
BIG-IP
May 7, 2025
High7.5F5

High [CVE-2025-35995] When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat…

When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-35995
BIG-IP
May 7, 2025
High8.7F5

High [CVE-2025-31644] When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell…

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-31644
BIG-IP
May 7, 2025
High7.1Omnissa

High [CVE-2025-25234] UAG: Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability.

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks. Affected product named by the advisory: Unified Access Gateway.

CVE-2025-25234
Unified Access Gateway
Apr 17, 2025
High7.8Omnissa

High [CVE-2025-25230] Horizon Client: Omnissa Horizon Client for Windows contains an LPE Vulnerability.

Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.

CVE-2025-25230
Horizon
Apr 16, 2025
High7.8Sophos

High [CVE-2024-13861] code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10

A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.

CVE-2024-13861
Unclassified
Apr 11, 2025
High7.8MS Server

High [CVE-2025-27743] Microsoft System Center Elevation of Privilege Vulnerability

Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: System Center Data Protection Manager 2019; System Center Data Protection Manager 2022; System Center Data Protection Manager 2025; System Center Operations Manager 2019; and 11 more. Affected products named by the advisory: System Center Operations Manager 2022; System Center Operations Manager 2025; System Center Orchestrator 2019; System Center Orchestrator 2022; and 7 more.

CVE-2025-27743
Unclassified
Apr 8, 2025