Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.7Red Hat

Medium [CVE-2026-62343] Denial of Service via heap buffer over-write in morphology operation with invalid kernel

Denial of Service via heap buffer over-write in morphology operation with invalid kernel. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-805.

CVE-2026-62343
Unclassified
Jul 29, 2026
Medium5.3Red Hat

Medium [CVE-2026-64685] Information Disclosure via Crafted Image File

Information Disclosure via Crafted Image File. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.

CVE-2026-64685
Unclassified
Jul 29, 2026
Medium4.2Red Hat

Medium [CVE-2026-15157] HTTP header injection via unvalidated blob-like body type property

HTTP header injection via unvalidated blob-like body type property. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-93. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-15157
Unclassified
Jul 29, 2026
Medium5.9Red Hat

Medium [CVE-2026-14643] Cross-user information disclosure due to improper Cache-Control directive parsing

Cross-user information disclosure due to improper Cache-Control directive parsing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-14643
Unclassified
Jul 29, 2026
Medium4.8Red Hat

Medium [CVE-2026-16728] Response desynchronization via retry interceptor with mismatched Content-Length

Response desynchronization via retry interceptor with mismatched Content-Length. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-16728
Unclassified
Jul 29, 2026
Medium6.8Red Hat

Medium [CVE-2026-54249] Information disclosure through unvalidated file references.

Information disclosure through unvalidated file references. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-918.

CVE-2026-54249
Unclassified
Jul 29, 2026
Medium6.8Red Hat

Medium [CVE-2026-46678] Server-Side Request Forgery (SSRF) bypass exposes cloud credentials.

Server-Side Request Forgery (SSRF) bypass exposes cloud credentials. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-918.

CVE-2026-46678
Unclassified
Jul 29, 2026
Medium6.5Red Hat

Medium [CVE-2026-65975] Remote clients can execute server tools with forged arguments due to improper message sanitization.

Remote clients can execute server tools with forged arguments due to improper message sanitization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected product named by the advisory: Lightspeed Core.

CVE-2026-65975
Unclassified
Jul 29, 2026
Medium4.7GitLab

Medium [CVE-2026-3093] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input.

CVE-2026-3093
Unclassified
Jul 29, 2026
Medium4.3GitLab

Medium [CVE-2026-4672] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.

CVE-2026-4672
Unclassified
Jul 29, 2026
Medium5.3GitLab

Medium [CVE-2026-6336] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check.

CVE-2026-6336
Unclassified
Jul 29, 2026
Medium6.5GitLab

Medium [CVE-2026-13113] Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.

CVE-2026-13113
Unclassified
Jul 29, 2026
Medium4.9GitLab

Medium [CVE-2026-14341] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint.

CVE-2026-14341
Unclassified
Jul 29, 2026
Medium4.3GitLab

Medium [CVE-2026-14351] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.

CVE-2026-14351
Unclassified
Jul 29, 2026
Medium4.3GitLab

Medium [CVE-2026-15077] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.

CVE-2026-15077
Unclassified
Jul 29, 2026
Medium4.3GitLab

Medium [CVE-2026-15831] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.

CVE-2026-15831
Unclassified
Jul 29, 2026
Medium5.4GitLab

Medium [CVE-2026-16553] GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries.

CVE-2026-16553
Unclassified
Jul 29, 2026
Medium5.9Red Hat

Medium [CVE-2026-13346] Arbitrary file installation via malicious package indexes

Arbitrary file installation via malicious package indexes. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:48788 with package python-pip-main-26.2-0.1.hum1.

CVE-2026-13346
Unclassified
Jul 29, 2026
Medium4.3Red Hat

Medium [CVE-2026-62995] JWT Malleability via Non-Standard Padding

JWT Malleability via Non-Standard Padding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1286. Red Hat lists fixing advisory RHSA-2026:48758 with package jaeger-main-2.20.0-0.8.hum1.

CVE-2026-62995
Unclassified
Jul 29, 2026
Medium4.8Red Hat

Medium [CVE-2026-16729] Cookie attribute injection allows bypassing security protections

Cookie attribute injection allows bypassing security protections. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-140. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-16729
Unclassified
Jul 29, 2026