VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Arbitrary command injection via maliciously crafted URL when --netrc-cmd is used. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Memory allocation with excessive without limits in the internal SVG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:5573 — update the affected packages (`sudo dnf update`).
Local File Disclosure via Path Traversal. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:5573 — update the affected packages (`sudo dnf update`).
Denial of service and potential arbitrary code execution via integer overflow in image processing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via specially crafted network requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via invalid clusterbus packet. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): valkey, valkey-main. Resolved in Red Hat advisory RHSA-2026:3507 — update the affected packages (`sudo dnf update`).
Data tampering and denial of service via improper null character handling in Lua scripts. Red Hat rates this important (CVSS 7.1). Weakness: CWE-170. Affected package(s): valkey. Resolved in Red Hat advisory RHSA-2026:3507 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution and Denial of Service via heap buffer overflow. Red Hat rates this moderate (CVSS 7.2). Weakness: CWE-122. Affected package(s): 389-ds-base, 389-ds:1.4, redhat-ds:11, dirsrv/dirsrv-container-rhel10:1772040913, redhat-ds:12. Resolved in Red Hat advisory RHSA-2026:3379 — update the affected packages (`sudo dnf update`).
Out of bounds read and write in Tint. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Out of bounds read in Media. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Inappropriate implementation in DevTools. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Unauthorized authentication via misconfigured mTLS CA chain. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
MLflow Use of Default Password Authentication Bypass Vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-798. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution via XWD file parsing vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`).
Remote code execution via heap-based buffer overflow in ICNS file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:4173 — update the affected packages (`sudo dnf update`).
Remote Code Execution via out-of-bounds write in XWD file parsing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`).
Remote Code Execution via uninitialized memory in PGM file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-908. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`).
Local privilege escalation via uncontrolled search path for plugins. Red Hat rates this important (CVSS 7.8). Weakness: CWE-427. Affected package(s): rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1776243249, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1776319453. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.