Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5QNAP

Medium [CVE-2025-29901] NULL pointer dereference vulnerability has been reported to affect File Station 5.

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later

CVE-2025-29901
Unclassified
Aug 26, 2025
Medium5.3F5

Medium [CVE-2025-54500] HTTP/2 implementation flaw

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54500
Unclassified
Aug 13, 2025
Medium6.5Check Point

Medium [CVE-2025-2028] Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country…

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVE-2025-2028
Unclassified
Aug 6, 2025
Medium5.0Check Point

Medium [CVE-2024-52885] The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated…

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

CVE-2024-52885
Unclassified
Aug 6, 2025
Medium6.8Sophos

Medium [CVE-2024-13973] post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

CVE-2024-13973
Sophos Firewall (XGS/SFOS)
Jul 21, 2025
Medium6.1Check Point

Medium [CVE-2024-24915] SmartConsole: Credentials are not cleared from memory after being used.

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

CVE-2024-24915
Security Management
Jun 29, 2025
Medium5.0pfSense

Medium [CVE-2025-53392] In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

CVE-2025-53392
pfSense CE
Jun 28, 2025
Medium6.5Check Point

Medium [CVE-2024-24916] Untrusted DLLs in the installer's directory

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

CVE-2024-24916
Unclassified
Jun 19, 2025
Medium6.5QNAP

Medium [CVE-2025-33035] path traversal vulnerability has been reported to affect File Station 5.

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-33035
Unclassified
Jun 6, 2025
Medium5.5QNAP

Medium [CVE-2025-29871] out-of-bounds read vulnerability has been reported to affect File Station 5.

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29871
Unclassified
Jun 6, 2025
Medium5.4QNAP

Medium [CVE-2024-56805] QTS: buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.

CVE-2024-56805
QTSQuTS hero
Jun 6, 2025
Medium5.4QNAP

Medium [CVE-2024-50406] License Center: cross-site scripting (XSS) vulnerability has been reported to affect License Center.

A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: License Center 1.9.49 and later

CVE-2024-50406
Unclassified
Jun 6, 2025
Medium6.7QNAP

Medium [CVE-2024-13087] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

CVE-2024-13087
Unclassified
Jun 6, 2025
Medium6.0F5

Medium [CVE-2025-43878] F5OS: When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-43878
F5OS / Distributed Cloud
May 7, 2025
Medium5.4Check Point

Medium [CVE-2024-52888] For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties

For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

CVE-2024-52888
Unclassified
Apr 27, 2025
Medium4.9Aruba

Medium [CVE-2025-27085] Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.

CVE-2025-27085
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
Medium5.4Aruba

Medium [CVE-2025-27084] vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.

CVE-2025-27084
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
Medium6.0Aruba

Medium [CVE-2025-27079] vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise.

CVE-2025-27079
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium6.5Aruba

Medium [CVE-2025-27078] vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.

CVE-2025-27078
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium5.5Aruba

Medium [CVE-2025-25041] vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients.

CVE-2025-25041
Virtual Intranet AccessWireless & Controllers
Apr 1, 2025