Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.7NetApp

High [CVE-2026-59874] Tar Vulnerability in NetApp Products

Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59874
Unclassified
Aug 28, 2026
High7.8NetApp

High [CVE-2026-49429 +2] June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49429CVE-2026-49430CVE-2026-49431
Unclassified
Aug 28, 2026
High7.1NetApp

High [CVE-2026-17106] Docker Engine Vulnerability in NetApp Products

Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-17106
Unclassified
Aug 28, 2026
High8.4NetApp

High [CVE-2026-44604 +1] Attr Vulnerability in NetApp Products

Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44604CVE-2026-54371
Unclassified
Aug 28, 2026
High7.3NetApp

High [CVE-2026-15571] Keycloak Vulnerability in NetApp Products

Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-15571
Unclassified
Aug 28, 2026
High7.0NetApp

High [CVE-2026-44604] RPM Vulnerability in NetApp Products

RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44604
Unclassified
Aug 28, 2026
High8.1NetApp

High [CVE-2026-54513] FasterXML Jackson Databind Vulnerability in NetApp Products

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54513
Unclassified
Aug 28, 2026
High7.2NetApp

High [CVE-2026-54370] Acl Vulnerability in NetApp Products

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54370
Unclassified
Aug 28, 2026
High8.3NetApp

High [CVE-2026-59250] Erlang/OTP Vulnerability in NetApp Products

Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59250
Unclassified
Aug 28, 2026
High7.6VMware Updated

High [CVE-2026-59284] Spring Cloud: There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 3.1.10 and earlier

CVE-2026-59284
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47893] Spring Framework: Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by…

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47893
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47889] Spring Framework: WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite…

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47889
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47888] Spring Framework: Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47888
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47886] Spring Framework: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47886
Tanzu / Spring
Aug 27, 2026
High7.7VMware Updated

High [CVE-2026-47879] Spring Cloud: Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto…

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 3.1.13 and earlier

CVE-2026-47879
Tanzu / Spring
Aug 27, 2026
High8.2VMware Updated

High [CVE-2026-47877] Spring Security: Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

CVE-2026-47877
Tanzu / Spring
Aug 27, 2026
High7.4VMware Updated

High [CVE-2026-47841] Spring Security: application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a di…

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.

CVE-2026-47841
Tanzu / Spring
Aug 26, 2026
High7.2VMware Updated

High [CVE-2026-47836] Spring Cloud: The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repos…

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.14 and earlier

CVE-2026-47836
Tanzu / Spring
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80537] fix off-by-one in rtrefcount btree root level validation

fix off-by-one in rtrefcount btree root level validation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-80537
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80530] fix exchange-range reflink flag clearing issue with INO1_WRITTEN

fix exchange-range reflink flag clearing issue with INO1_WRITTEN. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80530
Linux Kernel
Aug 26, 2026