VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4209 advisories across 32 monitored vendors.
.NET: improper input validation allows an attacker to elevate privileges locally. Red Hat rates this important (CVSS 7.3). Weakness: CWE-20. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
.NET: heap-based buffer overflow allows an attacker to elevate privileges locally. Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Sandbox escape in the Profile Backup component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Denial of Service via excessive IMAP bracing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
SQL/LDAP injection via incorrect safe filter interpretation with variable expansion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Other issue in the JavaScript Engine component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-475. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Incorrect boundary conditions in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`).
Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary Code Execution via Command-Line Argument Injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
llm CLI tool: Arbitrary code execution via code injection in --functions argument. Red Hat rates this important (CVSS 7.3). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Improper Authorization allows security bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-551. Affected package(s): tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`).
Authentication bypass via digest authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-303. Affected package(s): tomcat10-main, tomcat11-main, devspaces/server-rhel9:1780694994. Resolved in Red Hat advisory RHSA-2026:25123 — update the affected packages (`sudo dnf update`).
Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`).
Information disclosure via AJP secret timing discrepancy. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`).
Arbitrary file read via bypassed source path validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276, rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464, rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240, rhoai/odh-th06-rocm64-torch291-py312-rhel9:1782135346. Resolved in Red Hat advisory RHSA-2026:34456 — update the affected packages (`sudo dnf update`).
Arbitrary command execution via crafted links in system logs UI. Red Hat rates this important (CVSS 8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:21390 — update the affected packages (`sudo dnf update`).
"Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
stack overflow in recursive object merge. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`).
embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-20. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`).