Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat

Medium [CVE-2026-74463] Cache host clock rate at probe to prevent CCF prepare_lock deadlock

Cache host clock rate at probe to prevent CCF prepare_lock deadlock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-74463
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-74466] Close speculative mem read possibility

Close speculative mem read possibility. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74466
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-74540] fix UAF in l2cap_le_connect_rsp

fix UAF in l2cap_le_connect_rsp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74540
Linux Kernel
Aug 15, 2026
Critical9.8NetApp Updated

Critical [CVE-2026-31589] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 5.15 through 6.18.39 and 6.19.0 through 7.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31589
Unclassified
Aug 14, 2026
Critical9.8NetApp

Critical [CVE-2026-64534] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions prior to 5.10.261, 5.11.0 prior to 5.15.212, 5.16.0 prior to 6.1.178, 6.2.0 prior to 6.6.145, 6.7.0 prior to 6.12.97, 6.13.0 prior to 6.18.40, and 6.19.0 prior to 7.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-64534
Unclassified
Aug 14, 2026
Critical9.8NetApp

Critical [CVE-2026-64535] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 5.10.20 prior to 5.11, 5.11.3 prior to 5.12, 5.12 prior to 6.1.178, 6.2.0 prior to 6.6.145, 6.7.0 prior to 6.12.97, 6.13.0 prior to 6.18.40, and 6.19.0 prior to 7.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-64535
Unclassified
Aug 14, 2026
High8.8Red Hat

High [CVE-2026-63649] Privilege escalation via arbitrary configuration file loading

Privilege escalation via arbitrary configuration file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22.

CVE-2026-63649
Unclassified
Aug 14, 2026
High7.5Red Hat

High [CVE-2026-45699] Stack-based buffer overflow in copydir allows arbitrary code execution

Stack-based buffer overflow in copydir() allows arbitrary code execution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-45699
Unclassified
Aug 14, 2026
High7.5Red Hat Updated

High [CVE-2026-46603] Denial of Service via excessive memory allocation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. This is an Important severity flaw due to the potential for a remote attacker to trigger a denial of service. By providing a specially crafted VP8L image, an attacker can exploit a vulnerability in `golang.org/x/image/vp8l` that causes excessive memory allocation, leading to memory exhaustion in applications processing these images. This could impact the availability of services utilizing the affected component. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-46603
Unclassified
Aug 14, 2026
High7.8Red Hat Updated

High [CVE-2026-46439] Remote Code Execution via Recursive Server-Side Template Injection

Remote Code Execution via Recursive Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46439
Unclassified
Aug 14, 2026
High7.5Apache

High [CVE-2026-73633] Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The JSON plugin is an optional component; applications that do not use it, or use it without enabling JSON request-body handling, are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

CVE-2026-73633
Struts
Aug 14, 2026
High7.5Red Hat Updated

High [CVE-2026-72813] Denial of Service via empty Range header in GET requests

Denial of Service via empty Range header in GET requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected product named by the advisory: Red Hat OpenShift Update Service.

CVE-2026-72813
Unclassified
Aug 14, 2026
High7.5NetApp

High [CVE-2026-54876] OpenSSL Vulnerability in NetApp Products

OpenSSL versions 3.6.0 prior to 3.6.4 and 4.0.0 prior to 4.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54876
Unclassified
Aug 14, 2026
High7.1NetApp

High [CVE-2026-58086] FreeBSD Vulnerability in NetApp Products

FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged user in a jail that has permission to debug the target process to modify the jailed root user's ktrace(2) flags, or disable tracing outright. Successful exploitation of this vulnerability could lead to addition or modification of data or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58086
Unclassified
Aug 14, 2026
High7.3NetApp Updated

High [CVE-2026-7598] Libssh2 Vulnerability in NetApp Products

Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-7598
ONTAPActive IQ Unified ManagerONTAP Select
Aug 14, 2026
High8.2NetApp

High [CVE-2026-10543] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow privilege escalation with a specially crafted query. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-10543
Unclassified
Aug 14, 2026
High7.5NetApp

High [CVE-2026-58085] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD using wg(4) are susceptible to a vulnerability which when successfully exploited could allow a remote attacker who can send UDP packets to a WireGuard endpoint or intercept WireGuard packets bound for a FreeBSD host to inject forged or modified transport data packets into the tunnel or modify the ciphertext and authenticated data without detection by the receiver. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-58085
Unclassified
Aug 14, 2026
MediumRed Hat

Medium [CVE-2026-74250] Autodetect deploy interface fails to run cleaning

Autodetect deploy interface fails to run cleaning. Red Hat rates this moderate. Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-74250
Unclassified
Aug 14, 2026
Medium4.2Red Hat

Medium [CVE-2026-74247] SSRF via build archive_url in Quay build API

SSRF via build archive_url in Quay build API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74247
Unclassified
Aug 14, 2026
Medium5.9Red Hat

Medium [CVE-2026-74245] Unauthenticated exported logs download in Quay

Unauthenticated exported logs download in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74245
Unclassified
Aug 14, 2026