Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.2Red Hat

High [CVE-2026-54330] RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation

RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-54330
Unclassified
Aug 19, 2026
High8.5Red Hat

High [CVE-2026-39944] RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation

RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-327. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-39944
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-55192] Out-of-bounds read leads to memory disclosure or client crash

Out-of-bounds read leads to memory disclosure or client crash. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55192
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

Heap-buffer-overflow allows arbitrary code execution via crafted RPC response. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-55194
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55193] Remote code execution or client crash via malicious TS Gateway

Remote code execution or client crash via malicious TS Gateway. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55193
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55191] Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation

Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55191
Red Hat Enterprise Linux
Aug 19, 2026
High7.1Red Hat Updated

High [CVE-2026-75147] Information disclosure or denial of service via crafted AV1 RTP packet

Information disclosure or denial of service via crafted AV1 RTP packet. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75147
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-75146] Information disclosure and denial of service via out-of-bounds read in DASH demuxer

Information disclosure and denial of service via out-of-bounds read in DASH demuxer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75146
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75144] Memory corruption via crafted Dirac data unit

Memory corruption via crafted Dirac data unit. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75144
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75142] Stack Buffer Overflow in MPEG-PS Muxer

Stack Buffer Overflow in MPEG-PS Muxer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75142
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-76233] Arbitrary command execution via gleam manager command injection

Arbitrary command execution via gleam manager command injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-76233
Unclassified
Aug 19, 2026
High8.2Red Hat Updated

High [CVE-2026-76222] Arbitrary file creation via path traversal in.gitmodules submodule names

Arbitrary file creation via path traversal in.gitmodules submodule names. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-76222
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-76221] Arbitrary code execution via config-name injection

Arbitrary code execution via config-name injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76221
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-76220] Arbitrary command execution via crafted kwargs

Arbitrary command execution via crafted kwargs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76220
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-76219] Arbitrary File Overwrite via `git read-tree` option injection

Arbitrary File Overwrite via `git read-tree` option injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76219
Unclassified
Aug 19, 2026
High7.5Red Hat Updated

High [CVE-2026-76218] Remote Code Execution via malicious Git hooks

Remote Code Execution via malicious Git hooks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76218
Unclassified
Aug 19, 2026
High7.5Red Hat

High [CVE-2020-37267] Information disclosure via unredacted logging of authorization tokens

Information disclosure via unredacted logging of authorization tokens. Red Hat rates this important (CVSS 7.5). Weakness: CWE-538.

CVE-2020-37267
Unclassified
Aug 19, 2026
High7.8Red Hat

High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution

Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.

CVE-2026-43961
Unclassified
Aug 19, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html

unauthenticated remote memory leak via CockpitLang cookie in send_login_html. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-76235
Unclassified
Aug 19, 2026
High7.3Red Hat Updated

High [CVE-2026-58081] Heap-based buffer overflow in encoding modules

Heap-based buffer overflow in encoding modules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: php.

CVE-2026-58081
Red Hat Enterprise Linux
Aug 19, 2026