Skip to content
VulniPulse

Source directory

Security advisories, by vendor

Explore 32 supported vendors, their official security sources and tracked product platforms. Each vendor hub brings together source-linked advisories, CVE identifiers and remediation details where published.

VulniPulse organises vendor evidence; it is not the issuing authority. An advisory or product absent here is not proof that it is unaffected. Read our data and matching methodology.

Apache Software Foundation

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Platforms: HTTP Server (httpd), Tomcat, Messaging (ActiveMQ/Kafka/Pulsar), Struts, Airflow, Data & Analytics (Spark/Hadoop/Gravitino), Infra (APISIX/Traffic Server/CloudStack)

Atlassian

Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.

Platforms: Confluence, Jira, Bitbucket, Bamboo / Crowd / Fisheye

Check Point

Check Point is its own CVE Numbering Authority. VulniPulse ingests Check Point's CVEs from the NVD CNA feed (cve@checkpoint.com), each linking to its support.checkpoint.com advisory. Covers Quantum Security Gateway / Spark, the Gaia OS, Quantum Maestro, Harmony Endpoint / Mobile, CloudGuard and the Security Management server — its Quantum VPN/gateways were mass-exploited (CVE-2024-24919), a top network-security target.

Platforms: Quantum Gateway / Gaia, Harmony (Endpoint/Mobile), CloudGuard, Security Management

Cisco

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Platforms: ISE, Catalyst Center, Switches, Routers, Catalyst SD-WAN, IOS XE, Firewalls (ASA/FTD), Unified Comms

Commvault

Polled by parsing the official Commvault security-advisories index (documentation.commvault.com), which lists every CV_YYYY_MM_N advisory with its CVEs and dates. Advisory pages are fetched for new items to extract severity, impacted products and the Feature Release / Maintenance Release fix table.

Platforms: Backup & Recovery, Web Server / Command Center, HyperScale X, Commvault Cloud (Metallic)

Docker

Docker Inc. is its own CVE Numbering Authority. VulniPulse ingests Docker's CVEs from the NVD CNA feed (security@docker.com) — Docker Desktop, Docker CLI, Docker Model Runner and Docker Sandboxes — and merges in the open-source engine components that publish under their own project CNAs (Moby, the Docker Engine upstream; BuildKit; containerd) via a subject-anchored NVD keyword feed that drops the heavy 'third-party app runs in a Docker Compose stack' noise. Docker Desktop / Engine is a near-universal part of every developer and homelab stack.

Platforms: Docker Desktop, Docker Engine / Moby, BuildKit / Compose, Docker CLI / Scout

F5

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Platforms: BIG-IP, BIG-IP Next, BIG-IQ, NGINX, F5OS / Distributed Cloud

Fortinet

Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.

Platforms: FortiGate / FortiOS, FortiManager, FortiAnalyzer, FortiWeb, FortiClient, FortiProxy

GitLab

GitLab is its own CVE Numbering Authority and publishes prolifically — it ships coordinated security releases roughly every month, so VulniPulse ingests GitLab's CVEs from the NVD CNA feed (cve@gitlab.com), a high-volume, authoritative source where each record names the affected CE/EE version range. Covers GitLab Community Edition and Enterprise Edition (self-managed), plus GitLab Runner and Pages — self-hosted DevOps platforms that are a repeated RCE / auth-bypass target, so a patch-now audience.

Platforms: GitLab CE / EE, GitLab Runner, GitLab Pages

HPE Aruba Networking

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Platforms: AOS-CX Switches, AOS-Switch (ProVision), AOS-10 Gateways & APs, AOS-8 Mobility Controllers, Instant AP / InstantOS, ClearPass (NAC), Aruba Central, EdgeConnect SD-WAN, Fabric Composer, Virtual Intranet Access (VIA)

Ivanti

Polled via Ivanti's official Security Advisory blog RSS. Posts summarize each monthly/out-of-band advisory and link to the canonical Ivanti Security Advisory KB. Ivanti Connect Secure, Policy Secure and EPMM are frequent, high-priority exploitation targets.

Platforms: Connect Secure (VPN), Policy Secure, EPMM / MobileIron, Neurons, Endpoint Manager, Sentry

Juniper Networks

Juniper's advisory portal (kb.juniper.net) is a login-walled Salesforce app, so VulniPulse ingests Juniper SIRT (JSA) advisories from NVD, filtered to Juniper's own CNA (sirt@juniper.net) — official, machine-readable data with the affected Junos releases in each description. Junos on SRX/MX/EX/QFX and Junos Space are the common targets.

Platforms: SRX / Firewalls, MX / Routers, EX / QFX Switches, Junos OS, Junos Space, Secure Analytics (JSA), Session Smart Router

Microsoft Server

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Platforms: Windows Server, Exchange Server, SQL Server, SharePoint Server

MikroTik

MikroTik publishes official security announcements at mikrotik.com/supportsec, but has no machine-readable feed and its CVEs are assigned by several CNAs. VulniPulse joins NVD candidate metadata to the server-rendered official announcement index, then releases an alert only after fetching the linked article and verifying its CVE identity in the article heading or body. Covers RouterOS (v6/v7), SwOS, Winbox, The Dude and MikroTik router/switch hardware (hEX, CCR, CRS, cAP, wAP).

Platforms: RouterOS, SwOS (Switches), Winbox / The Dude, Wireless (cAP/wAP)

NetApp

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Platforms: ONTAP / System Manager, AFF / ASA / FAS, StorageGRID, E-Series / SANtricity, SolidFire / Element / HCI, SnapCenter, Active IQ Unified Manager, BlueXP / NetApp Console, Trident / Astra, ONTAP tools for VMware, OnCommand / Data Infrastructure Insights, Brocade SANnav / Fabric OS, NetApp tools & integrations

Netgate pfSense

Netgate maintains a dedicated Security Advisory index for pfSense (docs.netgate.com/advisories), but pfSense CVEs are assigned by MITRE and third-party researchers rather than a Netgate CNA — so VulniPulse ingests them from NVD (keyword-filtered to pfSense, dropped unless a pfSense/Netgate product is named) and links back to the Netgate advisory or pfSense reference. Covers pfSense CE (Community Edition) and pfSense Plus — a firewall/router at the network edge where a bug is directly internet-exposed.

Platforms: pfSense Plus, pfSense CE

NETGEAR

NETGEAR publishes official Security Advisories on kb.netgear.com, but the KB has no machine-readable feed and NETGEAR CVEs are assigned by a mix of NETGEAR's PSIRT and third-party researchers — so VulniPulse ingests them from NVD (keyword-filtered to NETGEAR, requiring a NETGEAR product in the description) and links each CVE back to its kb.netgear.com advisory when referenced. Covers the Orbi and Nighthawk router / WiFi lines, ReadyNAS, ProSAFE / Insight-managed switches and the cable-modem gateways — an enormous internet-facing SOHO and prosumer fleet that routinely ships remotely exploitable router bugs.

Platforms: Orbi (Mesh WiFi), Nighthawk Routers, Switches (ProSAFE/Insight), ReadyNAS

NetScaler (Citrix)

Polled via the official NetScaler blog RSS feed, filtered to security bulletin posts. Bulletin posts carry affected builds and link to the CTX security bulletin on Citrix Support (which sits behind a bot challenge and cannot be fetched directly).

Platforms: NetScaler ADC, NetScaler Gateway, NetScaler Console

Omnissa (ex-VMware EUC)

Omnissa (the former VMware End-User Computing division: Workspace ONE and Horizon) is its own CVE Numbering Authority. VulniPulse ingests Omnissa's CVEs from the NVD CNA feed, grouped by the official OMSA-YYYY-NNNN advisory each CVE references, then enriches severity, CVSS and impacted products from the official Omnissa Security Response index. Covers Workspace ONE UEM, Intelligent Hub, Access, Tunnel and Assist, Horizon 8 / Horizon Client, App Volumes and Unified Access Gateway (UAG) — UAG and Horizon are internet-facing and historically heavily probed.

Platforms: Workspace ONE UEM, Workspace ONE Apps (Hub/Tunnel/Assist), Horizon, Unified Access Gateway, App Volumes / DEM

Palo Alto Networks

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Platforms: PAN-OS / Panorama, GlobalProtect, Prisma, Cortex

Proxmox

Proxmox posts security advisories on its forum (no machine-readable feed) and its CVEs are assigned by MITRE / researchers rather than a Proxmox CNA — so VulniPulse ingests them from NVD (keyword-filtered to Proxmox, dropped unless a Proxmox product is named). Covers Proxmox Virtual Environment (VE), Proxmox Backup Server (PBS) and Proxmox Mail Gateway (PMG) — the homelab and SMB virtualization stack, complementing VMware/Omnissa coverage.

Platforms: Virtual Environment (VE), Backup Server (PBS), Mail Gateway (PMG)

QNAP

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Platforms: QTS, QuTS hero, Backup (HBS), Surveillance (QVR), Applications

Red Hat Linux

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Platforms: RHEL & SELinux, Linux Kernel, Web Servers & Proxies

SonicWall

SonicWall is its own CVE Numbering Authority. Its PSIRT portal (psirt.global.sonicwall.com) is a reCAPTCHA-gated JavaScript app with no stable public feed, so VulniPulse ingests SonicWall's CVEs from the NVD CNA feed (PSIRT@sonicwall.com), grouped by the official SNWLID advisory, with affected products and versions from each description and a link back to the SNWLID advisory. Covers SonicOS firewalls (Gen6/Gen7 TZ/NSa/NSsp/NSv), Secure Mobile Access (SMA 100/1000), SSL-VPN, NetExtender, Email Security and GMS/Analytics — SonicWall SSL-VPN is a frequent ransomware entry point.

Platforms: SonicOS Firewalls, Secure Mobile Access (SMA), SSL-VPN & Clients, Email Security, GMS / Analytics

Sophos

Sophos is its own CVE Numbering Authority. VulniPulse ingests Sophos's CVEs from the NVD CNA feed (security-alert@sophos.com), each linking to its sophos.com advisory. Covers Sophos Firewall (XG/XGS, SFOS), Intercept X / Sophos Central endpoint, Sophos UTM, Sophos Mobile, Sophos Connect VPN and the Web/Email appliances — its firewalls are a repeated mass-exploitation target (the 'Pacific Rim' campaign), so an MSP-heavy, alert-hungry community.

Platforms: Sophos Firewall (XGS/SFOS), Intercept X / Central, Sophos UTM, Sophos Mobile / Connect

Splunk

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Platforms: Splunk Enterprise, Splunk Cloud Platform, Universal Forwarder, ES / ITSI / SOAR

Synology

Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.

Platforms: DSM (DiskStation Manager), SRM (Router Manager), Applications, BeeStation, SSL VPN Client

Ubiquiti

Ubiquiti publishes Security Advisory Bulletins on its community site (community.ui.com), but there is no machine-readable feed and its CVEs are coordinated through HackerOne rather than a single Ubiquiti CNA — so VulniPulse ingests them from NVD (keyword-filtered to Ubiquiti) and links each CVE back to its community.ui.com bulletin when referenced. Covers UniFi Network / UniFi OS, the Dream Machine line (UDM/UDR/UCG), UniFi Protect, Access, Talk and Connect, plus EdgeRouter, EdgeSwitch, UISP and AmpliFi — an enormous internet-facing prosumer + SMB fleet that repeatedly ships max-severity (CVSS 10.0) flaws.

Platforms: UniFi Network / OS, UniFi Protect, UniFi Access / Talk / Connect, EdgeRouter / EdgeSwitch, UISP / airMAX

Veeam

Polled via the official Veeam Support KB Atom feed, filtered to security advisories (KB articles mentioning CVEs or vulnerabilities). KB pages are fetched for new items to extract build numbers and fixes.

Platforms: Backup & Replication, Veeam ONE, Service Provider Console, Agents, Backup for M365

VMware (Broadcom)

Broadcom's VMSA portal is a JavaScript app with no stable public feed, so VulniPulse ingests VMware CVEs from NVD filtered to VMware's own CNAs (security@vmware.com and Broadcom's successor CNA) — official, CNA-published data covering ESXi, vCenter Server, NSX, Aria/vRealize, Cloud Foundation, Workstation/Fusion and VMware Tools. Each entry links back to the Broadcom/VMware advisory when NVD carries the reference.

Platforms: ESXi / vSphere, vCenter Server, NSX, Cloud Foundation, Aria / vRealize, Workstation & Fusion, VMware Tools, Avi / VeloCloud, Tanzu / Spring

WatchGuard

WatchGuard is not its own NVD CNA and its PSIRT portal has no machine-readable feed, so VulniPulse ingests WatchGuard's CVEs from NVD (keyword-filtered to WatchGuard, requiring a WatchGuard product in the description) and links each CVE back to the wgrd-psirt advisory when referenced. Covers Fireware OS on the Firebox firewall line, WatchGuard System Manager, the WatchGuard Agent / EPDR endpoint and AuthPoint MFA — SMB firewalls previously mass-exploited by the Cyclops Blink botnet, so a patch-now audience.

Platforms: Firebox / Fireware, WatchGuard Agent / EPDR, AuthPoint MFA, System Manager

Zyxel

Zyxel runs its own CNA (security@zyxel.com.tw), but a large share of Zyxel CVEs are assigned by MITRE and third-party researchers — so VulniPulse ingests them from NVD by keyword (which covers more than the CNA feed alone), requiring a Zyxel product in the description, and links back to the zyxel.com security advisory when referenced. Covers the USG FLEX / ATP / VPN firewalls, Nebula-managed access points, the GS-series switches and the VMG/EMG gateways — an SMB fleet that is a chronic KEV / actively-exploited target.

Platforms: Firewalls (USG FLEX/ATP), Nebula / Access Points, Switches (GS-series), Gateways (VMG/EMG)