VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
Use-after-free in the IPC component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
Sandbox escape in the Messaging System component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Sandbox escape due to incorrect boundary conditions in the Graphics component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
Sandbox escape due to integer overflow in the Graphics component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
Mitigation bypass in the DOM: Security component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`).
BUG() in pskb_expand_head() as part of calipso_skbuff_setattr(). Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-190. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:5727 — update the affected packages (`sudo dnf update`).
Fix use-after-free when updating multicast route stats. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3966 — update the affected packages (`sudo dnf update`).
use rc_pageoff for memcpy byte offset. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:2722 — update the affected packages (`sudo dnf update`).
Out of bounds memory access in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
disable SVA when CONFIG_X86 is set. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-820. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`).
Denial of Service via malformed image processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-395. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service due to excessive memory usage from compressed HTTP request bodies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Unauthorized access to secrets via Lua script credential leakage. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Information disclosure and denial of service via missing XML validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-112. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
React Router has Path Traversal in File Session Storage. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap-based buffer overflow in js_typed_array_constructor function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
@remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects. Red Hat rates this important (CVSS 8). Weakness: CWE-79. Affected package(s): odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, odf4/odf-cli-rhel9:1781557189, odf4/rook-ceph-rhel9-operator:1781557496. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`).
@remix-run/react: React Router SSR XSS in ScrollRestoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-79. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1778666987, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, ansible-automation-platform, automation-platform-ui, rhoai/odh-dashboard-rhel9:1772093424. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`).