Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

84 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.2VMware

Medium [CVE-2026-22721] vCenter: VMware Aria Operations contains a privilege escalation vulnerability.

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.

CVE-2026-22721
vCenterAria / vRealize
Feb 25, 2026
Medium6.2VMware

Medium [CVE-2025-62349] Salt contains an authentication protocol version downgrade weakness that can

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

CVE-2025-62349
Unclassified
Jan 30, 2026
Medium5.3VMware

Medium [CVE-2025-22228 +1] The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

CVE-2025-22228CVE-2025-22234
Unclassified
Jan 22, 2026
Medium6.8VMware

Medium [CVE-2026-22718] The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

CVE-2026-22718
Unclassified
Jan 14, 2026