Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.7VMware Updated

High [CVE-2026-41012] BOSH: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and…

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic between the BOSH Director and vCenter can establish a malicious server impersonating the vCenter REST API. When the BOSH Director makes CPI calls to perform routine cloud infrastructure operations, the attacker captures the vCenter administrator username and password transmitted via HTTP Basic authentication. The vulnerability stems from insufficient authentication security in the communication protocol between BOSH Director and vCenter. While HTTPS may be used, the lack of proper certificate validation and pinning allows attackers to successfully impersonate vCenter endpoints. Because vCenter credentials typically grant full administrative control over the entire virtualization estate, successful credential capture yields complete takeover of every VM, datastore, and network the CPI manages. This exposure exists on every CPI call (including routine deployment operations, not just when tags are configured) and cannot be mitigated by supplying a CA certificate alone. Affected product named by the advisory: bosh-vsphere-cpi-release.

CVE-2026-41012
ESXiTanzu / SpringvSphere
Aug 29, 2026
Critical9.0Vendor: HighSynology Updated

Critical [CVE-2026-40541 +2] improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM

Synology has released a security update for the Synology Chat Server package in DSM to address multiple vulnerabilities: CVE-2026-40541 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. CVE-2026-9491 allows remote authenticated users to obtain non-sensitive information. Please refer to the ' Affected products named by the advisory: Synology Chat Server for DSM 7.3; Synology Chat Server for DSM 7.2.2; Synology Chat Server for DSM 7.2.1.

CVE-2026-40541CVE-2026-9491CVE-2026-9548
DSM (DiskStation Manager)
Aug 28, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-82327] out-of-bounds write in repo_write via unvalidated directory id from vertical/paged.solv filelist data

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with.solv repository cache files. When libsolv rewrites a.solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted.solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value. The vulnerable code path is the vertical/paged (lazily loaded) filelist decoder used by repo_write(), reached only when a consumer (e.g. dnf/libdnf) rewrites a.solv cache after having loaded one containing SOLVABLE_FILELIST data stored with KEY_STORAGE_VERTICAL_OFFSET. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-129. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more.

CVE-2026-82327
Red Hat Enterprise Linux
Aug 28, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-78174] WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

CVE-2026-78174
System Manager
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19315] type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19315
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-13086] stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

CVE-2026-13086
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19313] heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19313
Firebox / Fireware
Aug 27, 2026
Critical9.3WatchGuard Updated

Critical [CVE-2026-19318] stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVE-2026-19318
Firebox / Fireware
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-59313] Spring Framework: Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent…

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Affected product named by the advisory: Spring Framework.

CVE-2026-59313
Tanzu / Spring
Aug 27, 2026
Critical9.1VMware Updated

Critical [CVE-2026-59283] Spring Framework: Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnera…

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8

CVE-2026-59283
Tanzu / Spring
Aug 27, 2026
Critical9.6VMware Updated

Critical [CVE-2026-59354] Spring Security: In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registra…

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). Affected product named by the advisory: Spring Security (OAuth2 Authorization Server module).

CVE-2026-59354
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47892] Spring Framework: WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header pr…

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47892
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47891] Spring Framework: Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the…

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47891
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47890] Spring Framework: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view…

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47890
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47884] Spring Framework: Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47884
Tanzu / Spring
Aug 27, 2026
Critical9.4VMware Updated

Critical [CVE-2026-59270] Spring Security: Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative cre…

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.

CVE-2026-59270
Tanzu / Spring
Aug 27, 2026
High8.6WatchGuard Updated

High [CVE-2026-78612] WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

CVE-2026-78612
System Manager
Aug 27, 2026
High8.6WatchGuard Updated

High [CVE-2026-78613] WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

CVE-2026-78613
System Manager
Aug 27, 2026
High8.4WatchGuard Updated

High [CVE-2026-78610] WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.

CVE-2026-78610
System Manager
Aug 27, 2026
High8.7WatchGuard Updated

High [CVE-2026-13108] WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service

WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service.

CVE-2026-13108
System Manager
Aug 27, 2026