Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.3Red Hat Updated

Medium [CVE-2026-14678] Information disclosure via buffer over-read in pg_trgm

Information disclosure via buffer over-read in pg_trgm. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-126. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14678
Red Hat Enterprise Linux
Aug 13, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-14672] User existence oracle in SCRAM authentication

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Unauthenticated attackers can verify if a specific user exists by observing the authentication iteration count, provided the targeted user is configured with a non-default scram_iterations value. A moderate-severity vulnerability in PostgreSQL allows unauthenticated attackers to enumerate valid users. By observing discrepancies in SCRAM authentication responses, attackers can identify users configured with a non-default scram_iterations count, which may facilitate targeted brute-force attacks. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-204. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14672
Red Hat Enterprise Linux
Aug 13, 2026
Medium4.2Red Hat Updated

Medium [CVE-2026-14666] Row security caching disregards role modifications leading to unauthorized data access

Row security caching disregards role modifications leading to unauthorized data access. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-524. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14666
Red Hat Enterprise Linux
Aug 13, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-14663] PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers

PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:54751 with package postgresql18-main-18.6-0.1.hum1, postgresql17-main-17.11-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; and 1 more.

CVE-2026-14663
Red Hat Enterprise Linux
Aug 13, 2026
Medium6.3Red Hat

Medium [CVE-2026-73584] Privileged file corruption and denial of service via insecure temporary file handling

Privileged file corruption and denial of service via insecure temporary file handling. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.

CVE-2026-73584
Red Hat Enterprise Linux
Aug 13, 2026
Medium6.6Red Hat

Medium [CVE-2026-73583] Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr

Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.

CVE-2026-73583
Red Hat Enterprise Linux
Aug 13, 2026
Medium6.3Red Hat

Medium [CVE-2026-73585] Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack

Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-73585
Unclassified
Aug 13, 2026
Medium5.4Red Hat

Medium [CVE-2026-73621] Arbitrary File Truncation via Commit.count Argument Injection

Arbitrary File Truncation via Commit.count() Argument Injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73621
Unclassified
Aug 13, 2026
Medium6.5Red Hat

Medium [CVE-2026-73619] Arbitrary file read vulnerability via `Repo.archive `

Arbitrary file read vulnerability via `Repo.archive()`. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73619
Unclassified
Aug 13, 2026
Medium6.6Red Hat

Medium [CVE-2026-19694] Heap-based Buffer Overflow in Wireshark

Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-122.

CVE-2026-19694
Unclassified
Aug 13, 2026
Medium4.7Red Hat

Medium [CVE-2026-19695] Stack-based Buffer Overflow in Wireshark

Stack-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-121.

CVE-2026-19695
Unclassified
Aug 13, 2026
Medium6.6Red Hat

Medium [CVE-2026-19696] Out-of-bounds Write in Wireshark

Out-of-bounds Write in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787.

CVE-2026-19696
Unclassified
Aug 13, 2026
Medium6.5Red Hat

Medium [CVE-2026-18728] Integer underflow in iscsiuio IPv4 DHCP parsing

Integer underflow in iscsiuio IPv4 DHCP parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-18728
Unclassified
Aug 13, 2026
Medium5.5Red Hat

Medium [CVE-2026-68454] Fix handling of AIF enable without AISB

Fix handling of AIF enable without AISB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68454
Linux Kernel
Aug 13, 2026
Low3.5Red Hat

Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in

Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.

CVE-2026-55987
Unclassified
Aug 13, 2026
Low2.7Red Hat

Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API

Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.

CVE-2026-55984
Unclassified
Aug 13, 2026
Low3.8Red Hat Updated

Low [CVE-2026-6469] Incorrect ownership assignment allows unauthorized statistics modification

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. The overall impact is limited, as standard DROP TABLE operations still correctly remove the affected objects. This flaw has a Low impact on Red Hat products. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-708. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-6469
Red Hat Enterprise Linux
Aug 13, 2026
Low3.8Red Hat Updated

Low [CVE-2026-16241] Denial of Service via integer underflow

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability causes the client to overwrite a large memory region, leading to a temporary denial of service (DoS). This Low impact flaw in PostgreSQL ECPG affects client applications. The limited scope to client-side disruption and the prerequisite of elevated server privileges contribute to its lower severity. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-16241
Red Hat Enterprise Linux
Aug 13, 2026
Low3.8Red Hat Updated

Low [CVE-2026-14673] PostgreSQL amcheck: Privilege escalation via untrusted search path

PostgreSQL amcheck: Privilege escalation via untrusted search path. Red Hat rates this low (CVSS 3.8). Weakness: CWE-426. Red Hat lists fixing advisory RHSA-2026:54751 with package postgresql18-main-18.6-0.1.hum1, postgresql17-main-17.11-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-14673
Unclassified
Aug 13, 2026
Low0.0Red Hat

Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations

Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.

CVE-2026-73626
Unclassified
Aug 13, 2026