Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.3GitLab

Low [CVE-2025-9486] GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.

CVE-2025-9486
Unclassified
Aug 12, 2026
UnratedCisco

Advisory [CVE-2026-20030 +14] Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Crosswork Security Hardening Release: August 2026 Critical 10.0 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability High 7.5 Cisco Unified Intelligence Center SQL Injection Vulnerability Medium 6.5 Cisco RoomOS Stack Overflow Vulnerability 6.1 Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability 5.4 5.3 Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability 5.0 To fully remediate the vulnerabilities that were disclosed on August 19, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.

CVE-2026-20030CVE-2026-20177CVE-2026-20231+12
Unclassified
Aug 12, 2026
Critical9.1Apache

Critical [CVE-2026-71290] Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVE-2026-71290
Unclassified
Aug 11, 2026
Critical9.4SonicWall

Critical [CVE-2026-66145 +5] GMS: unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which…

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

CVE-2026-66145CVE-2026-66146CVE-2026-18634+3
GMS / Analytics
Aug 11, 2026
Critical9.9Red Hat

Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison

Server-Side Request Forgery via incorrect IPv6 comparison. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-918.

CVE-2026-73213
Unclassified
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-65791] Windows iSCSI Target Service Remote Code Execution Vulnerability

Windows iSCSI Target Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-65791
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62893] Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-62893
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62878] Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-62878
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62815] Microsoft QUIC Remote Code Execution Vulnerability

Microsoft QUIC Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-62815
Windows Server
Aug 11, 2026
Critical9.1Apache

Critical [CVE-2026-69223] Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF)

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-69223
Unclassified
Aug 11, 2026
Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73269
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend

Arbitrary code execution via shell command injection in SSH backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-5917
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding

Data corruption and unauthorized modification via JSON Pointer escape decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-386.

CVE-2026-29036
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink

Arbitrary code execution via use-after-free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19560
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19559] Arbitrary code execution via use after free in HTML

Arbitrary code execution via use after free in HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19559
Unclassified
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip

Sandbox escape via use-after-free in TabStrip. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.

CVE-2026-19557
Unclassified
Aug 11, 2026
High7.3Red Hat

High [CVE-2026-19558] Arbitrary code execution via malicious extension installation

Arbitrary code execution via malicious extension installation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.

CVE-2026-19558
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8

Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19556
Unclassified
Aug 11, 2026