Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.3NetApp Updated

High [CVE-2026-7598] Libssh2 Vulnerability in NetApp Products

Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-7598
ONTAPActive IQ Unified ManagerONTAP Select
Aug 14, 2026
High8.2NetApp

High [CVE-2026-10543] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow privilege escalation with a specially crafted query. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-10543
Unclassified
Aug 14, 2026
High7.5NetApp

High [CVE-2026-58085] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD using wg(4) are susceptible to a vulnerability which when successfully exploited could allow a remote attacker who can send UDP packets to a WireGuard endpoint or intercept WireGuard packets bound for a FreeBSD host to inject forged or modified transport data packets into the tunnel or modify the ciphertext and authenticated data without detection by the receiver. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-58085
Unclassified
Aug 14, 2026
MediumRed Hat

Medium [CVE-2026-74250] Autodetect deploy interface fails to run cleaning

Autodetect deploy interface fails to run cleaning. Red Hat rates this moderate. Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-74250
Unclassified
Aug 14, 2026
Medium4.2Red Hat

Medium [CVE-2026-74247] SSRF via build archive_url in Quay build API

SSRF via build archive_url in Quay build API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74247
Unclassified
Aug 14, 2026
Medium5.9Red Hat

Medium [CVE-2026-74245] Unauthenticated exported logs download in Quay

Unauthenticated exported logs download in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74245
Unclassified
Aug 14, 2026
Medium5.9Red Hat

Medium [CVE-2026-74244] Stripe webhook accepts forged events without signature verification in Quay

Stripe webhook accepts forged events without signature verification in Quay. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74244
Unclassified
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-74243] Unauthenticated secscan notification endpoint in Quay when PSK is unset

Unauthenticated secscan notification endpoint in Quay when PSK is unset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74243
Unclassified
Aug 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-74242] Repository notification UUID IDOR in Quay API

Repository notification UUID IDOR in Quay API. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-639. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74242
Unclassified
Aug 14, 2026
Medium4.8Red Hat

Medium [CVE-2026-74241] LDAP referral filter injection in Quay external LDAP authentication

LDAP referral filter injection in Quay external LDAP authentication. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-90. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74241
Unclassified
Aug 14, 2026
Medium5.4Red Hat

Medium [CVE-2026-74240] JWT claim validation bypasses in Quay federated robot and SSO authentication

JWT claim validation bypasses in Quay federated robot and SSO authentication. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287. Affected products named by the advisory: Red Hat OpenShift Update Service; Red Hat Quay 3.

CVE-2026-74240
Unclassified
Aug 14, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation

Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49263
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends

Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49282
Red Hat Enterprise Linux
Aug 14, 2026
Medium4.6Vendor: LowRed Hat Updated

Medium [CVE-2026-66807] dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning

dangerouslySetInnerHTML with unescaped subscription identifiers in SharedResourceWarning. Red Hat rates this low (CVSS 4.6). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66807
Unclassified
Aug 14, 2026
Medium6.7Red Hat Updated

Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem

Server-Side Request Forgery via unvalidated URL in remote fetching subsystem. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-918. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46380
Unclassified
Aug 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-19879] HTTP response header integrity issue due to character truncation

HTTP response header integrity issue due to character truncation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-681. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7; and 2 more.

CVE-2026-19879
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-19880] Path traversal allows arbitrary log file creation

Path traversal allows arbitrary log file creation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 16 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 12 more.

CVE-2026-19880
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-73051] HTTP Request Smuggling via malformed HTTP/1.1 headers

HTTP Request Smuggling via malformed HTTP/1.1 headers. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Update Service; Red Hat package: keylime-agent-rust; and 1 more. Affected products named by the advisory: Red Hat package: trustee.

CVE-2026-73051
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72816] IP Spoofing via RealIP Middleware allows bypassing access controls

IP Spoofing via RealIP Middleware allows bypassing access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 18 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 14 more.

CVE-2026-72816
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation

IP spoofing via X-Forwarded-For header manipulation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:49718 with package cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 19 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Serverless; and 15 more.

CVE-2026-72817
Red Hat Enterprise Linux
Aug 14, 2026