VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
prototype pollution in _.unset and _.omit functions. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1321. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, openshift-gitops, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, openshift4/ose-console-rhel9:1770831186, multicluster-engine/console-mce-rhel9:1776223790. Resolved in Red Hat advisory RHSA-2026:3869 — update the affected packages (`sudo dnf update`).
Denial of Service via corrupt or malicious record. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`).
POP3 command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).
IMAP command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).
Enhance Handling of URIs (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.4). Weakness: CWE-1287. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0896 — update the affected packages (`sudo dnf update`).
Enhance Certificate Checking (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`).
Nodejs denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`).
Nodejs uninitialized memory exposure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-497. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`).
Nodejs file permissions bypass. Red Hat rates this important (CVSS 7.1). Weakness: CWE-281. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via a crafted XBM image file. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:3058 — update the affected packages (`sudo dnf update`).
Arbitrary file overwrite via Unicode path collision race condition. Red Hat rates this important (CVSS 8.8). Weakness: CWE-367. Affected package(s): devspaces/udi-rhel9:1774451954, rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056, linux-sgx. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`).
Path traversal via malicious tar archives. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Unsafe pickle file handling in Ply. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Affected package(s): openshift4/ose-ironic-rhel9:1772029626, openshift4/ose-ironic-rhel9:1774266098, openshift4/ose-ironic-rhel9:1773138063, openshift4/ose-ironic-rhel9:1772477045, openshift4/ose-ironic-rhel9:1772176749. Resolved in Red Hat advisory RHSA-2026:3402 — update the affected packages (`sudo dnf update`).
Denial of Service and potential code execution via use-after-free vulnerability. Red Hat rates this important (CVSS 7.6). Weakness: CWE-416. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).
Arbitrary code execution and denial of service via malicious server. Red Hat rates this important (CVSS 7.6). Weakness: CWE-416. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).
Arbitrary code execution and denial of service via client-side heap buffer overflow. Red Hat rates this important (CVSS 7.6). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).
Heap buffer overflow leads to denial of service and potential code execution. Red Hat rates this important (CVSS 7.6). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).
Denial of Service and potential code execution via client-side heap buffer overflow. Red Hat rates this important (CVSS 7.6). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).
Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.. Red Hat rates this important (CVSS 7.6). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:2952 — update the affected packages (`sudo dnf update`).