Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8Red Hat Updated

High [CVE-2026-18305] Remote Code Execution via TIF file parsing integer overflow

Remote Code Execution via TIF file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18305
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18304] Arbitrary code execution via crafted TIF file parsing

Arbitrary code execution via crafted TIF file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18304
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18303] Remote code execution via TIF file parsing vulnerability

Remote code execution via TIF file parsing vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18303
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18302] Remote code execution via TIF file parsing heap-based buffer overflow

Remote code execution via TIF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18302
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18301] Remote code execution via PSD file parsing integer overflow

Remote code execution via PSD file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18301
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18300] Remote code execution via integer overflow in HDR file parsing

Remote code execution via integer overflow in HDR file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: gimp; Red Hat package: gegl04.

CVE-2026-18300
Red Hat Enterprise Linux
Aug 20, 2026
High8.8Red Hat Updated

High [CVE-2026-18299] Remote Code Execution via Use-After-Free in rtpsbcdepay

Remote Code Execution via Use-After-Free in rtpsbcdepay. Red Hat rates this important (CVSS 8.8). Weakness: CWE-386. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.8, gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-18299
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18298] Remote code execution via heap-based buffer overflow in PNG file parsing

Remote code execution via heap-based buffer overflow in PNG file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7, gstreamer1-plugins-good-0:1.26.7-2.el10_2.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18298
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18297] Arbitrary code execution via OGG file parsing buffer overflow

Arbitrary code execution via OGG file parsing buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59097 with package gstreamer1-plugins-base-0:1.16.1-6.el8_10.1, gstreamer1-plugins-base-0:1.26.7-2.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18297
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18296] Remote Code Execution via MRF file parsing heap-based buffer overflow

Remote Code Execution via MRF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7, gstreamer1-plugins-good-0:1.26.7-2.el10_2.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18296
Unclassified
Aug 20, 2026
High8.8Red Hat Updated

High [CVE-2026-18295] Remote code execution via MRF file parsing

Remote code execution via MRF file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-18295
Unclassified
Aug 20, 2026
High8.1Red Hat

High [CVE-2026-77176] Insufficient validation of CreateContainer mount and storage rules in genpolicy

Insufficient validation of CreateContainer mount and storage rules in genpolicy. Red Hat rates this important (CVSS 8.1). Weakness: CWE-73. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-77176
Unclassified
Aug 20, 2026
High7.4Vendor: MediumRed Hat

High [CVE-2026-19611] Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access. This issue has Moderate impact. Successful exploitation depends on accounts using fullwidth or other NFKC-compatibility characters in passwords and on the feasibility of password guessing against the deployed hash algorithm. Red Hat severity: Moderate — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-173. Affected Red Hat products: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-19611
Unclassified
Aug 20, 2026
High7.5Apache

High [CVE-2026-63043] Relative Path Traversal vulnerability in Apache InLong

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63043
Unclassified
Aug 20, 2026
High8.1Apache

High [CVE-2026-63042] Files or Directories Accessible to External Parties vulnerability in Apache InLong

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63042
Unclassified
Aug 20, 2026
High8.1Apache

High [CVE-2026-63040] Files or Directories Accessible to External Parties vulnerability in Apache InLong

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63040
Unclassified
Aug 20, 2026
High8.2Red Hat Updated

High [CVE-2026-49825] URL bypass vulnerability in Cleaner via missing xlink:href

URL bypass vulnerability in Cleaner via missing xlink:href. Red Hat rates this important (CVSS 8.2). Weakness: CWE-166. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 20 more. Affected products named by the advisory: Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 16 more.

CVE-2026-49825
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-61898] Arbitrary code execution via shell injection

Arbitrary code execution via shell injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-61898
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-61897] Local privilege escalation via incomplete privilege drop in language helper scripts

Local privilege escalation via incomplete privilege drop in language helper scripts. Red Hat rates this important (CVSS 7.8). Weakness: CWE-273.

CVE-2026-61897
Unclassified
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-73198] Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read

Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-73198
Red Hat Enterprise Linux
Aug 20, 2026