VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Remote Code Execution via ICO File Parsing Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`).
Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via Stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
org.springframework.data/spring-data-geode: Spring Data Geode: Path traversal vulnerability allows arbitrary file write via import snapshot functionality.. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file read/write via malicious archive hardlink creation. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-22. Affected package(s): rhtas/rekor-search-ui-rhel9:1773308315, network-observability/network-observability-console-plugin-rhel9:1774431617, devspaces/dashboard-rhel9:1774476526, devspaces/code-rhel9:1774448966. Resolved in Red Hat advisory RHSA-2026:5447 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via H.264 unpacketizer heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730). Red Hat rates this important (CVSS 7.4). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution in guest virtual machine via file system modification. Red Hat rates this important (CVSS 9.3). Weakness: CWE-281. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children). Red Hat rates this important (CVSS 9.6). Weakness: CWE-116. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`).
PDF object injection via unsanitized input in addJS method. Red Hat rates this important (CVSS 9.6). Weakness: CWE-94. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via unsanitized `locate` output. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary command execution via unsanitized network interface parameter. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via unlimited XML entity expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`).
Denial of Service due to heap buffer overflow when parsing a crafted h5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`).
Rack Directory Traversal via Rack:Directory. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Zip Slip Vulnerability in nltk Leading to Code Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-ta-lmes-job-rhel9:1776271296. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Integer overflow in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Fix use-after-free in iscsit_dec_conn_usage_count(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`).