VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4206 advisories across 32 monitored vendors.
Remote Code Execution in SAMR. Red Hat rates this important (CVSS 9). Weakness: CWE-78. Affected package(s): samba, rhcos. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`).
Remote Code Execution via Server-Side Template Injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-917. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-787. Affected package(s): libsolv, libsolv-main. Resolved in Red Hat advisory RHSA-2026:28236 — update the affected packages (`sudo dnf update`).
Remote code execution via heap-buffer-overflow in gdi_CacheToSurface. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via crafted tar header with large entry size. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Path traversal via crafted symlinks allows arbitrary file access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected package(s): perl:5.32, perl-Archive-Tar. Resolved in Red Hat advisory RHSA-2026:30852 — update the affected packages (`sudo dnf update`).
Denial of service against AD DC WINS server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Linux kernel: smb: client: reject userspace cifs.spnego descriptions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected package(s): kernel, kernel-rt, rhcos, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:33219 — update the affected packages (`sudo dnf update`).
Security restriction bypass via malformed HTTP Host header. Red Hat rates this critical (CVSS 6.5). Weakness: CWE-1289. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1782132660, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1782133865, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1782132444, satellite/iop-host-inventory-rhel9:1780414237, satellite/foreman-mcp-server-rhel9:1780492012, rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782420349. Resolved in Red Hat advisory RHSA-2026:34526 — update the affected packages (`sudo dnf update`).
Amplification vulnerabilities via self-pointed glue records. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:20334 — update the affected packages (`sudo dnf update`).
Unbounded resend loop in BIND 9 resolver. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-835. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:20334 — update the affected packages (`sudo dnf update`).
Packet of death with DNSCrypt. Red Hat rates this moderate (CVSS 5.9). Affected package(s): unbound-main. Resolved in Red Hat advisory RHSA-2026:20357 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via unauthorized multipart upload access. Red Hat rates this critical (CVSS 9). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack(). Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-415. Affected package(s): libarchive-main. Resolved in Red Hat advisory RHSA-2026:30333 — update the affected packages (`sudo dnf update`).
Denial of Service via uncontrolled recursion in AST Serialization. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-674. Affected package(s): rust-main. Resolved in Red Hat advisory RHSA-2026:22934 — update the affected packages (`sudo dnf update`).
propagate shared-frag marker through frag-transfer helpers. Red Hat rates this important (CVSS 7). Weakness: CWE-664. Affected package(s): rhcos, kernel-rt, kernel, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`).
Cross-Site Scripting via HTML parsing bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation via incorrect Punycode label processing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1289. Affected package(s): rhacm2/observatorium-rhel9:1782157471, rhacm2/prometheus-alertmanager-rhel9:1782156920, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, rhacm2/thanos-rhel9:1782465412, rhacm2/grafana-dashboard-loader-rhel9:1782383255, rhacm2/acm-prometheus-config-reloader-rhel9:1782157632. Resolved in Red Hat advisory RHSA-2026:35830 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via Cross-Site Scripting. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): opentelemetry-collector, cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9:1782839193, cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9:1782839981, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, cluster-observability-operator/monitoring-console-plugin-rhel9:1782838476. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`).