Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-1485] GLib Vulnerability in NetApp Products
Multiple NetApp products incorporate GLib. GLib versions through 2.86.3 and 2.87.0 through 2.87.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low OTP Invalidation Missing Upon Regeneration
OTP Invalidation Missing Upon Regeneration
Low [CVE-2025-14847] MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)
MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)
Low [CVE-2025-54821] Trusted hosts bypass via SSH
CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00 Affected products named by the advisory: FortiSASE.
Low Stored Cross-Site Scripting Vulnerability
Stored Cross-Site Scripting Vulnerability
Low [CVE-2025-31514] Insertion of Sensitive 2FA Information in logs and debug command
CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00 Affected products named by the advisory: FortiProxy.
Low [CVE-2025-25250] Information Disclosure on SSLVPN endpoint
CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL. Revised on 2026-06-15 00:00:00 Affected products named by the advisory: FortiSASE.