Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5GitLab

Medium [CVE-2026-15174] GitLab: Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15174
Unclassified
Jul 8, 2026
Medium4.7GitLab

Medium [CVE-2026-15173] GitLab: pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15173
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15172] GitLab: FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15172
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15171] GitLab: SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15171
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15170] GitLab: Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15170
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15169] GitLab: UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15169
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15166] GitLab: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15166
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15165] GitLab: TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15165
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15164] GitLab: Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15164
Unclassified
Jul 8, 2026
Medium5.5GitLab

Medium [CVE-2026-15163] GitLab: Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service Affected product named by the advisory: GitLab.

CVE-2026-15163
Unclassified
Jul 8, 2026
Medium6.5NetApp

Medium [CVE-2026-50229 +1] June 2026 Apache Tomcat Vulnerabilities in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100, 7.0.0 through 7.0.109 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-50229CVE-2026-55956
Unclassified
Jul 3, 2026
Medium6.5NetApp

Medium [CVE-2026-55955] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, and 9.0.13 through 9.0.118 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-55955
Unclassified
Jul 3, 2026
Medium6.5NetApp

Medium [CVE-2026-39827] Golang.Org/X/Crypto Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Org/X/Crypto versions prior to 0.52.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-39827
Unclassified
Jun 26, 2026
Medium6.9NetApp

Medium [CVE-2026-2303] MongoDB Drivers Vulnerability in NetApp Products

Multiple NetApp products incorporate MongoDB Drivers. MongoDB Drivers versions prior to 1.17.7 and 2.0.0-alpha1 prior to 2.4.2 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-2303
Unclassified
Jun 26, 2026
Medium5.5GitLab

Medium [CVE-2026-11968] GitLab: Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit Affected product named by the advisory: GitLab.

CVE-2026-11968
Unclassified
Jun 24, 2026
Medium6.1VMware

Medium [CVE-2026-47833] setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow.

setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and read every password hash on the host via the read-only /etc bind mount. This is a container-to-host confidentiality break affecting every bpm-managed job. Affected versions: bpm-release, all versions prior to v1.4.30.

CVE-2026-47833
Unclassified
Jun 18, 2026
Medium5.3NetApp

Medium [CVE-2026-44618] Apache CXF Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache CXF. Apache CXF versions prior to 3.6.11, 4.0.0 prior to 4.1.6, and 4.2.0 prior to 4.2.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44618
Active IQ Unified Manager
Jun 18, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45170] Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS…

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

CVE-2026-45170
Unclassified
Jun 12, 2026
Medium4.7NetApp

Medium [CVE-2026-27456] Util-linux Vulnerability in NetApp Products

Multiple NetApp products incorporate util-linux. Util-linux versions prior to 2.41.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27456
Active IQ Unified Manager
Jun 12, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45178] Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.

CVE-2026-45178
Unclassified
Jun 11, 2026