Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5F5

Medium [CVE-2025-47148] When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity…

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47148
BIG-IP
Oct 15, 2025
Medium6.5Aruba

Medium [CVE-2025-37148] vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

CVE-2025-37148
AOS-10Instant APWireless & ControllersInstant
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37145] Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility…

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37145
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37143] arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility…

An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37143
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37142] Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating…

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37142
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium6.2Aruba

Medium [CVE-2025-37138] authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8…

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37138
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium6.5Aruba

Medium [CVE-2025-37137] Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility…

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

CVE-2025-37137
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
Medium6.5QNAP

Medium [CVE-2025-44012] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later

CVE-2025-44012
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-44011] Qsync: NULL pointer dereference vulnerability has been reported to affect Qsync Central.

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44011
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-44007] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44007
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-33034] Qsync: path traversal vulnerability has been reported to affect Qsync Central.

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-33034
Applications
Oct 3, 2025
Medium4.9Aruba

Medium [CVE-2025-37131] vulnerability in EdgeConnect SD-WAN ECOS could

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

CVE-2025-37131
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.5Aruba

Medium [CVE-2025-37130] vulnerability in the command-line interface of EdgeConnect SD-WAN could

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.

CVE-2025-37130
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.7Aruba

Medium [CVE-2025-37129] vulnerable feature in the command line interface of EdgeConnect SD-WAN could

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.

CVE-2025-37129
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.8Aruba

Medium [CVE-2025-37128] vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

CVE-2025-37128
EdgeConnect SD-WAN
Sep 16, 2025
Medium5.4pfSense

Medium [CVE-2025-34178] In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related…

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

CVE-2025-34178
pfSense CE
Sep 9, 2025
Medium5.4pfSense

Medium [CVE-2025-34177] In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related…

In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

CVE-2025-34177
pfSense CE
Sep 9, 2025
Medium4.3pfSense

Medium [CVE-2025-34176] In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory…

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

CVE-2025-34176
pfSense CE
Sep 9, 2025
Medium6.1pfSense

Medium [CVE-2025-34175] In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without…

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.

CVE-2025-34175
pfSense CE
Sep 9, 2025
Medium5.4pfSense

Medium [CVE-2025-34174] In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric…

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.

CVE-2025-34174
pfSense CE
Sep 9, 2025