Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-13117] Denial of service or memory leakage via incomplete TLS guard
Denial of service or memory leakage via incomplete TLS guard. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.
Medium [CVE-2026-60074] Date::Manip: Incorrect date parsing leads to logic errors
Date::Manip: Incorrect date parsing leads to logic errors. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-681.
Medium [CVE-2026-59328] Spring Boot: Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Bro…
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Medium [CVE-2026-59327] Spring Boot: Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain str…
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reload endpoint, which accepts and executes arbitrary class bytes on the target application. Anyone able to read the.launch file (via filesystem access, a workspace backup, or a shared VCS repository) can extract the secret and use it to achieve remote code execution against the associated Spring Boot application. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Medium [CVE-2026-10723] ISC BIND Vulnerability in NetApp Products
ISC BIND versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-10822] ISC BIND Vulnerability in NetApp Products
ISC BIND versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-49844] Apache Log4j Vulnerability in NetApp Products
Apache Log4j versions 2.13.1 through 2.25.4 and version 2.26.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-15995] IBM Cognos Analytics Vulnerability in NetApp Products
The IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant used by authorized analysts to query report summaries and perform related tasks. Refer to the vendor advisory for additional information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
Medium [CVE-2026-51081] cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Medium [CVE-2026-41854] Spring Framework Vulnerability in NetApp Products
Spring Framework versions 7.0.0 through 7.0.7 and 6.2.0 through 6.2.18 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-7771] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Client and Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on all platforms are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.
Medium [CVE-2026-1299] CPython Vulnerability in NetApp Products
Certain version of CPython are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-41417] IBM Db2 Vulnerability in NetApp Products
IBM Db2 server versions 11.5.0 through 11.5.9 on Linux are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.
Medium [CVE-2026-22007 +2] July 2026 IBM Db2 IBM Semeru Vulnerabilities in NetApp Products
IBM Db2 Client and Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are susceptible to vulnerabilities in IBM Semeru 21.0.10.0 and earlier. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp states there is no workaround available at this time.
Medium [CVE-2026-10695] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 12.1.0 through 12.1.4 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.
Medium [CVE-2026-15757] security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.
Medium [CVE-2026-49426] FreeBSD Vulnerability in NetApp Products
All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an attacker with the ability to debug a process to produce misleading audit trails. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.
Medium [CVE-2026-49421] FreeBSD Vulnerability in NetApp Products
All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an attacker to delete files outside the intended directory tree. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.
Medium [CVE-2026-49424] FreeBSD Vulnerability in NetApp Products
FreeBSD 14.3, 14.4 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged user to observe a small amount of uninitialized kernel stack data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp states there is no workaround available at this time.
Medium [CVE-2026-40023] Apache Log4cxx Vulnerability in NetApp Products
Apache Log4cxx versions prior to 1.7.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.