Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.3MS Server

High [CVE-2026-47634] Microsoft SharePoint Server Spoofing Vulnerability

Microsoft SharePoint Server Spoofing Vulnerability Affected products named by the advisory: Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-47634
SharePoint Server
Jun 9, 2026
High7.9MS Server

High [CVE-2026-47656] Windows Boot Manager Security Feature Bypass Vulnerability

Windows Boot Manager Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-47656
Windows Server
Jun 9, 2026
High7.8Vendor: CriticalMS Server

High [CVE-2026-48574] Windows Media Remote Code Execution Vulnerability

Windows Media Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-48574
Windows Server
Jun 9, 2026
High7.0MS Server

High [CVE-2026-42836] Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42836
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-42905] Windows DWM Core Library Elevation of Privilege Vulnerability

Windows DWM Core Library Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42905
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-42916] NT OS Kernel Elevation of Privilege Vulnerability

NT OS Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42916
Windows Server
Jun 9, 2026
High7.5MS Server

High [CVE-2026-42913] Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42913
Windows Server
Jun 9, 2026
High8.1MS Server

High [CVE-2026-42981] Windows Performance Monitor Remote Code Execution Vulnerability

Windows Performance Monitor Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42981
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-42986] Microsoft Graphics Component Elevation of Privilege Vulnerability

Microsoft Graphics Component Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42986
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-44809] Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-44809
Windows Server
Jun 9, 2026
High8.4Vendor: CriticalMS Server

High [CVE-2026-44810] Microsoft Cryptographic Services Elevation of Privilege Vulnerability

Microsoft Cryptographic Services Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-44810
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-42983] Windows DWM Core Library Elevation of Privilege Vulnerability

Windows DWM Core Library Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-42983
Windows Server
Jun 9, 2026
High8.1Vendor: CriticalMS Server

High [CVE-2026-42987] Windows Deployment Services (WDS) Remote Code Execution

Windows Deployment Services (WDS) Remote Code Execution Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42987
Windows Server
Jun 9, 2026
High8.6QNAP

High [CVE-2025-59382 +16] QuTS hero: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later Affected products named by the advisory: QuTScloud. Affected products named by the advisory: QVP 2.7.1; QuTS cloud c5.2.8; QTS version 5.2.7; QuTS hero h5.2.8.

CVE-2025-59382CVE-2025-62858CVE-2025-66273+14
QTSQuTS hero
Jun 9, 2026
High8.1VMware

High [CVE-2026-41855] Spring Framework: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sp…

In an untrusted JMS environment, org.springframework.jms.support.converter. MappingJackson2MessageConverter and org.springframework.jms.support.converter. JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41855
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-40984] Micrometer HTTP server instrumentations DoS vulnerability

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

CVE-2026-40984
Unclassified
Jun 9, 2026
High8.7QNAP

High [CVE-2025-62851 +3] QuMagie: missing authorization vulnerability has been reported to affect QuMagie.

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later Affected products named by the advisory: License Center. Affected products named by the advisory: QuMagie 2.8.2; License Center 1.8.56.

CVE-2025-62851CVE-2026-26236CVE-2026-26237+1
Applications
Jun 9, 2026
High7.4Check Point

High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.

CVE-2026-50752
Unclassified
Jun 8, 2026
High7.2Docker

High [CVE-2026-41567] Docker Engine: Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images Affected products named by the advisory: moby/v2/daemon; docker/daemon.

CVE-2026-41567
Docker Engine / Moby
Jun 5, 2026
High7.5NetApp

High [CVE-2026-40972 +3] April 2026 Spring Boot Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Spring Boot. Spring Boot versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.3.0 through 3.3.18, and 2.7.0 through 2.7.32 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). OnCommand Insight: Affected only by CVE-2026-40975. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40972CVE-2026-40973CVE-2026-40974+1
OnCommand / Data Infrastructure Insights
Jun 5, 2026