Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

240 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7VMware

Low [CVE-2026-41000] Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVE-2026-41000
Unclassified
Jun 11, 2026
Low3.7VMware

Low [CVE-2026-41694] Spring Security: Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses wit…

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41694
Tanzu / Spring
Jun 10, 2026
Low3.3Vendor: HighMS Server

Low [CVE-2026-45485] Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-45485
SharePoint Server
Jun 9, 2026
Low3.9Vendor: HighMS Server

Low [CVE-2026-45642] Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45642
Windows Server
Jun 9, 2026
Low3.7VMware

Low [CVE-2026-41852] Spring Framework: vulnerability in Spring Expression Language (SpEL) evaluation logic

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected product named by the advisory: Spring Framework.

CVE-2026-41852
Tanzu / Spring
Jun 9, 2026
Low3.7VMware

Low [CVE-2026-41848] Spring Framework: Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a…

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected product named by the advisory: Spring Framework.

CVE-2026-41848
Tanzu / Spring
Jun 9, 2026
Low3.7NetApp

Low [CVE-2026-2391] Qs Vulnerability in NetApp Products

Multiple NetApp products incorporate qs. Qs versions 6.7.0 through 6.14.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-2391
Unclassified
May 15, 2026
Low2.1Fortinet

Low [CVE-2026-44278] Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

CVE-2026-44278
FortiClient
May 12, 2026
Low3.1VMware

Low [CVE-2026-22741] Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: - the application is using Spring MVC or Spring WebFlux - the application is configuring the resource chain support with caching enabled - the application adds support for encoded resources resolution - the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVE-2026-22741
Unclassified
Apr 29, 2026
Low3.7VMware

Low [CVE-2026-40969] The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status…

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.

CVE-2026-40969
Unclassified
Apr 28, 2026
Low2.5NetApp

Low [CVE-2026-35388] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions prior to 10.3 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-35388
Unclassified
Apr 24, 2026
Low3.6NetApp

Low [CVE-2026-35386] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions prior to 10.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-35386
AFF / ASA / FAS
Apr 24, 2026
Low3.5GitLab

Low [CVE-2026-3254] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox.

CVE-2026-3254
GitLab CE / EE
Apr 22, 2026
Low2.7GitLab

Low [CVE-2025-9957] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks.

CVE-2025-9957
GitLab CE / EE
Apr 22, 2026
Low3.7VMware

Low [CVE-2026-22746] Spring Security: Vulnerability in Spring Spring Security.

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked. This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVE-2026-22746
Tanzu / Spring
Apr 22, 2026
Low3.7Apache

Low [CVE-2026-32690] Apache Airflow: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user…

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented

CVE-2026-32690
Airflow
Apr 18, 2026
Low3.7NetApp Updated

Low [CVE-2026-28387] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-28387
AFF / ASA / FASElement Software
Apr 17, 2026
Low2.5Fortinet

Low [CVE-2026-27316] Credential disclosure in LDAP configuration web page.

CVSSv3 Score: 2.5 An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection. Revised on 2026-04-14 00:00:00

CVE-2026-27316
Unclassified
Apr 14, 2026
Low2.2Fortinet

Low [CVE-2026-21741] Open Redirection via Import CSV option

CVSSv3 Score: 2.2 An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file. Revised on 2026-04-14 00:00:00

CVE-2026-21741
FortiNAC
Apr 14, 2026
Low2.7GitLab

Low [CVE-2026-4916] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

CVE-2026-4916
GitLab CE / EE
Apr 8, 2026