VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4207 advisories across 32 monitored vendors.
Security flaw in org.keycloak/keycloak-services. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-303. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`).
Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-603. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`).
Information disclosure via OIDC token introspection endpoint audience bypass. Red Hat rates this moderate (CVSS 6.5). Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`).
Unauthorized account takeover via WebAuthn token replay. Red Hat rates this moderate (CVSS 6.8). Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`).
Out of bounds read in GPU. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation in the Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Mitigation bypass in the DOM: Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-358. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Spoofing issue in the Form Autofill component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-472. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via pre-authentication code injection. Red Hat rates this critical (CVSS 10). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution via command injection in Git branch name processing. Red Hat rates this important (CVSS 8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
extend the writable skb range per key. Red Hat rates this important (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`).
Arbitrary Code Execution via Malicious JSON Deserialization. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation via Kubernetes Gateway API provider configuration bypass. Red Hat rates this important (CVSS 8.3). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
command injection when decompressing .tgz archives. Red Hat rates this moderate (CVSS 7). Weakness: CWE-78. Affected package(s): vim. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`).
Uninitialized memory disclosure via `websocket.close()` with `TypedArray`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): dotnet8, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1782761244, dotnet10, discovery/discovery-ui-rhel9:1782166952, dotnet9. Resolved in Red Hat advisory RHSA-2026:34374 — update the affected packages (`sudo dnf update`).
Read root-owned files as an unprivileged user. Red Hat rates this important (CVSS 7.8). Weakness: CWE-269. Affected package(s): kernel, rhcos, kernel-rt, openshift, kpatch-patch, cri-o. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`).
Privilege escalation via improper CPU cache isolation. Red Hat rates this important (CVSS 7). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality. Red Hat rates this important (CVSS 8.2). Weakness: CWE-124. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via specially crafted certificate. Red Hat rates this important (CVSS 9.1). Weakness: CWE-475. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.