Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.8NetApp

Medium [CVE-2026-22801] Libpng Vulnerability in NetApp Products

Multiple NetApp products incorporate libpng. Libpng versions 1.6.26 prior to 1.6.54 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22801
Unclassified
Jan 30, 2026
Medium6.0NetApp

Medium [CVE-2026-0672] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-0672
Element SoftwareActive IQ Unified Manager
Jan 30, 2026
Medium5.5NetApp

Medium [CVE-2025-40027] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-40027
ONTAPActive IQ Unified ManagerONTAP Select
Jan 23, 2026
Medium5.3VMware

Medium [CVE-2025-22228 +1] The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

CVE-2025-22228CVE-2025-22234
Unclassified
Jan 22, 2026
Medium5.5Aruba

Medium [CVE-2025-37185] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface and thereby make unauthorized arbitrary configuration changes to the host.

CVE-2025-37185
EdgeConnect SD-WAN
Jan 14, 2026
Medium6.8VMware

Medium [CVE-2026-22718] The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

CVE-2026-22718
Unclassified
Jan 14, 2026
Medium6.5Aruba

Medium [CVE-2025-37177] AOS-10: arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either…

An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

CVE-2025-37177
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Jan 13, 2026
Medium6.5Aruba

Medium [CVE-2025-37176] command injection vulnerability in AOS-8

A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.

CVE-2025-37176
AOS-8 MobilityWireless & ControllersArubaOS
Jan 13, 2026
Medium6.5Fortinet

Medium [CVE-2025-58693] improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0…

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

CVE-2025-58693
Unclassified
Jan 13, 2026
Medium6.5NetApp

Medium [CVE-2023-2283] Libssh Vulnerability in NetApp Products

Multiple NetApp products incorporate Libssh. Libssh versions 0.9.1 prior to 0.9.7 and 0.10.0 prior to 0.10.5 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-2283
Unclassified
Dec 24, 2025
Medium6.5Check Point

Medium [CVE-2025-8305] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

CVE-2025-8305
Unclassified
Dec 22, 2025
Medium6.5Check Point

Medium [CVE-2025-8304] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.

CVE-2025-8304
Unclassified
Dec 22, 2025
Medium5.8Aruba

Medium [CVE-2025-37159] vulnerability in the web management interface of the AOS-CX OS user authentication service could

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

CVE-2025-37159
AOS-CXSwitches (AOS-CX)
Nov 18, 2025
Medium6.7Aruba

Medium [CVE-2025-37158] AOS-CX: command injection vulnerability exists in the AOS-CX Operating System.

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

CVE-2025-37158
AOS-CXSwitches (AOS-CX)
Nov 18, 2025
Medium6.8Aruba

Medium [CVE-2025-37156] ArubaOS-CX: platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software.

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.

CVE-2025-37156
AOS-CXSwitches (AOS-CX)
Nov 18, 2025
Medium4.3Atlassian

Medium [CVE-2025-22178] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVE-2025-22178
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22177] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

CVE-2025-22177
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22176] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

CVE-2025-22176
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22175] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

CVE-2025-22175
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22174] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVE-2025-22174
Jira
Oct 22, 2025