VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4181 advisories across 32 monitored vendors.
Cross-Site Scripting vulnerability via untrusted React Server Component redirects. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-79. Affected package(s): rhoai/odh-mod-arch-automl-rhel9:1782722421, rhoai/odh-mod-arch-mlflow-rhel9:1782132932, rhoai/odh-mod-arch-autorag-rhel9:1782722485, rhoai/odh-mod-arch-maas-rhel9:1782722695, rhoai/odh-mod-arch-model-registry-rhel9:1782722726, rhoai/odh-mod-arch-eval-hub-rhel9:1782722438. Resolved in Red Hat advisory RHSA-2026:34456 — update the affected packages (`sudo dnf update`).
Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20. Affected package(s): webkit2gtk3, webkitgtk4. Resolved in Red Hat advisory RHSA-2026:25918 — update the affected packages (`sudo dnf update`).
An app may be able to access sensitive user data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected package(s): webkit2gtk3, webkitgtk4. Resolved in Red Hat advisory RHSA-2026:25918 — update the affected packages (`sudo dnf update`).
Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-693. Affected package(s): webkit2gtk3, webkitgtk4. Resolved in Red Hat advisory RHSA-2026:25918 — update the affected packages (`sudo dnf update`).
Inappropriate implementation in Accessibility. Red Hat rates this important (CVSS 4.3). Weakness: CWE-1021. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Uninitialized Use in Dawn. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Out of bounds read in ANGLE. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Insufficient validation of untrusted input in Codecs. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Uninitialized Use in Skia. Red Hat rates this important (CVSS 6.8). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Insufficient validation of untrusted input in Input. Red Hat rates this important (CVSS 6.8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
out-of-bounds read/write in GLX ChangeDrawableAttributes. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`).
use-after-free information disclosure in CreateSaverWindow(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-416. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`).
Arbitrary command execution via insufficient file argument sanitization. Red Hat rates this important (CVSS 8.3). Weakness: CWE-88. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`).
AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Stack buffer overflow allows local code execution or denial of service. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-121. Affected package(s): rrdtool. Resolved in Red Hat advisory RHSA-2026:34155 — update the affected packages (`sudo dnf update`).
Denial of Service via crafted input due to insufficient validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, poppler, rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-cuda-rhel9:1782352847, poppler-main. Resolved in Red Hat advisory RHSA-2026:29952 — update the affected packages (`sudo dnf update`).
Arbitrary Code Execution via crafted discovery URI bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Unauthorized Broker Management via Incorrect Default Permissions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-276. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Information disclosure via unauthenticated BrokerInfo command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.