Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-19014] Denial of Service via uncontrolled resource consumption in Connect authorization endpoint
Denial of Service via uncontrolled resource consumption in Connect authorization endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19012] Authenticated denial of service via configuration entry
Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges
Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.
Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.
Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction
Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.
Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium
Sandbox escape via out-of-bounds write in Chromium. Red Hat rates this important (CVSS 9). Weakness: CWE-787.
Critical [CVE-2026-19155] Sandbox escape via use-after-free in Payments
Sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-19137] Google Chrome on Android: Sandbox escape via use after free in WebGL
Google Chrome on Android: Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…
@nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Execution via Zip-Slip vulnerability in self-hosted remote cache. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Critical [CVE-2026-5134] Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability
Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.
High [CVE-2026-70632] Arbitrary Code Execution in CFHD Decoder via Crafted AVI File
Arbitrary Code Execution in CFHD Decoder via Crafted AVI File. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-70628] Arbitrary code execution via crafted WTV file in DVB subtitle parser
Arbitrary code execution via crafted WTV file in DVB subtitle parser. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-71430] Denial of Service due to excessive string length in replacements
Denial of Service due to excessive string length in replacements. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.
High [CVE-2026-19177] Sandbox escape via crafted HTML page
Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8). Weakness: CWE-1289.
High [CVE-2026-19175] Remote sandbox escape via use-after-free in Payments
Remote sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19174] Arbitrary code execution via crafted HTML page
Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-19171] Sandbox escape via use-after-free in Media component
Sandbox escape via use-after-free in Media component. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-19166] Sandbox escape due to use-after-free in Web Authentication
Sandbox escape due to use-after-free in Web Authentication. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.