Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

302 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low2.9Red Hat

Low [CVE-2026-40228] Unintended output to user terminals via logger command

Unintended output to user terminals via logger command. Red Hat rates this low (CVSS 2.9). Weakness: CWE-117. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40228
Unclassified
Apr 10, 2026
Low3.5Red Hat

Low [CVE-2026-33551] Privilege escalation through EC2 credential creation

Privilege escalation through EC2 credential creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected package(s): openstack-keystone. Resolved in Red Hat advisory RHSA-2026:28044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-33551
Unclassified
Apr 7, 2026
Low3.7Red Hat

Low [CVE-2026-28387] Arbitrary code execution due to use-after-free in DANE TLSA authentication

Arbitrary code execution due to use-after-free in DANE TLSA authentication. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1341. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28387
Unclassified
Apr 7, 2026
Low3.7Red Hat

Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim

Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37977
Unclassified
Apr 6, 2026
Low2.2Red Hat

Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions

Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35388
Unclassified
Apr 2, 2026
Low3.1Red Hat

Low [CVE-2026-35387] Information disclosure due to unintended cryptographic algorithm usage

Information disclosure due to unintended cryptographic algorithm usage. Red Hat rates this low (CVSS 3.1). Weakness: CWE-115. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35387
Unclassified
Apr 2, 2026
Low3.6Red Hat

Low [CVE-2026-35386] Arbitrary command execution via shell metacharacters in username

Arbitrary command execution via shell metacharacters in username. Red Hat rates this low (CVSS 3.6). Weakness: CWE-78. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35386
Unclassified
Apr 2, 2026
Low3.7Red Hat

Low [CVE-2026-34073] Security bypass due to improper DNS name constraint validation

Security bypass due to improper DNS name constraint validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): python-cryptography-main. Resolved in Red Hat advisory RHSA-2026:7295 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34073
Unclassified
Mar 31, 2026
Low3.3Red Hat

Low [CVE-2026-21715] Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions

Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-425. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-21715
Unclassified
Mar 30, 2026
Low3.8Red Hat

Low [CVE-2026-21716] Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.

Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix.. Red Hat rates this low (CVSS 3.8). Weakness: CWE-279. Affected package(s): nodejs20-main, nodejs25-main, nodejs24, nodejs22-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-21716
Unclassified
Mar 30, 2026
Low3.1Red Hat

Low [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation

Server-Side Request Forgery via OIDC token endpoint manipulation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4874
Unclassified
Mar 26, 2026
Low3.7Red Hat

Low [CVE-2026-28753] NGINX Plus and NGINX Open Source: Request manipulation via header injection in SMTP upstream requests

NGINX Plus and NGINX Open Affected products named by the advisory: nginx-main; Red Hat Enterprise Linux.

CVE-2026-28753
Unclassified
Mar 24, 2026
Low3.4Red Hat

Low [CVE-2026-4718] Undefined behavior in the WebRTC: Signaling component

Undefined behavior in the WebRTC: Signaling component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-475. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4718
Unclassified
Mar 24, 2026
Low3.4Red Hat

Low [CVE-2026-4719] Incorrect boundary conditions in the Graphics: Text component

Incorrect boundary conditions in the Graphics: Text component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-805. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4719
Unclassified
Mar 24, 2026
Low3.3Red Hat

Low [CVE-2026-3479] Python pkgutil.get_data(): Path Traversal via improper resource argument validation

Python pkgutil.get_data(): Path Traversal via improper resource argument validation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3479
Unclassified
Mar 18, 2026
Low2.5Red Hat

Low [CVE-2025-13462] `tarfile` module misinterprets crafted tar archives leading to data integrity issues

`tarfile` module misinterprets crafted tar archives leading to data integrity issues. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-13462
Unclassified
Mar 12, 2026
Low3.3Red Hat

Low [CVE-2025-70873] Information Disclosure via Crafted ZIP File

Information Disclosure via Crafted ZIP File. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908. Affected package(s): sqlite-main. Resolved in Red Hat advisory RHSA-2026:7656 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70873
Unclassified
Mar 12, 2026
Low2.7Red Hat

Low [CVE-2026-3911] org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint

org.keycloak.services.resources.admin. UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint. Red Hat rates this low (CVSS 2.7). Weakness: CWE-359. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3911
Red Hat Enterprise Linux
Mar 11, 2026
Low3.3Red Hat

Low [CVE-2025-69647] infinite loop in readelf via crafted binary with malformed DWARF loclists data

infinite loop in readelf via crafted binary with malformed DWARF loclists data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-835. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69647
Unclassified
Mar 9, 2026
Low3.3Red Hat

Low [CVE-2025-69648] infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

infinite loop in readelf via crafted binary with malformed DWARF.debug_rnglists data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-835. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69648
Unclassified
Mar 9, 2026