Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat

High [CVE-2026-67855] Denial of Service via heap use-after-free

Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-67855
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function

Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-67857
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server

Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67858
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67859] Denial of Service via Discovery/LDS handling

Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67859
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67862] Denial of Service via buffer-overflow

Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67862
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing

don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.

CVE-2026-64564
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component

Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-67861
Unclassified
Aug 4, 2026
High8.2Red Hat

High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path

Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.

CVE-2026-67860
Unclassified
Aug 4, 2026
MediumRed Hat

Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation

Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.

CVE-2026-18785
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser

Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-18401
Unclassified
Aug 4, 2026
Medium6.5Zyxel

Medium [CVE-2026-8508] improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

CVE-2026-8508
Unclassified
Aug 4, 2026
Medium5.5Red Hat

Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.

CVE-2026-51400
Unclassified
Aug 4, 2026
High8.8Apache

High [CVE-2026-68981] Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

CVE-2026-68981
NiFi
Aug 3, 2026
High7.7Apache

High [CVE-2026-62354] Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.

CVE-2026-62354
NiFi
Aug 3, 2026
Low2.3Apache

Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVE-2026-68980
NiFi
Aug 3, 2026