Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.9NETGEAR

Medium [CVE-2026-11739] command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. Affected products named by the advisory: MR60; MR70; MR90; MS60; and 4 more. Affected products named by the advisory: MS70; MS90; RAX20; RAX200.

CVE-2026-11739
Unclassified
Aug 11, 2026
Medium4.3NETGEAR

Medium [CVE-2026-11737] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software functionality. Affected products named by the advisory: RAX20; RAX41; RAX41v2; RAX42; and 4 more. Affected products named by the advisory: RAX42v2; RAX43; RAX43v2; RAX45.

CVE-2026-11737
Unclassified
Aug 11, 2026
Medium4.9NETGEAR

Medium [CVE-2026-11814] command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. Affected products named by the advisory: BE9300; MR60; MS60; R6700AX; and 4 more. Affected products named by the advisory: RAX10; RAX120; RAX120v2; RAX20.

CVE-2026-11814
Unclassified
Aug 11, 2026
Medium4.3Red Hat

Medium [CVE-2026-71193] cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler

cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-71193
Unclassified
Aug 11, 2026
Medium4.3Red Hat

Medium [CVE-2026-71194] mDNS NOTIFY handler DoS via pool-blind zone lookup

mDNS NOTIFY handler DoS via pool-blind zone lookup. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-71194
Unclassified
Aug 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-73067] Denial of Service due to crafted data model

Denial of Service due to crafted data model. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-73067
Unclassified
Aug 11, 2026
Medium6.4Red Hat

Medium [CVE-2026-72745] Information disclosure and memory corruption via malformed Kerberos GSS Wrap token

Information disclosure and memory corruption via malformed Kerberos GSS Wrap token. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-72745
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.0Red Hat

Medium [CVE-2026-33922] Arbitrary file deletion via path traversal in Offline archives functionality

Arbitrary file deletion via path traversal in Offline archives functionality. Red Hat rates this moderate (CVSS 6). Weakness: CWE-22.

CVE-2026-33922
Unclassified
Aug 11, 2026
Medium5.2Red Hat

Medium [CVE-2026-33921] Information disclosure and arbitrary packet sending via insecure access restrictions

Information disclosure and arbitrary packet sending via insecure access restrictions. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-1188.

CVE-2026-33921
Unclassified
Aug 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-71218] Unbounded peer-controlled allocation in iperf3 JSON_read allows unauthenticated remote memory exhaustion

Unbounded peer-controlled allocation in iperf3 JSON_read() allows unauthenticated remote memory exhaustion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-789. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-71218
Unclassified
Aug 11, 2026
Medium4.3Red Hat

Medium [CVE-2026-19519] denial of service via unchecked type assertion in RPM header parser

denial of service via unchecked type assertion in RPM header parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Advanced Cluster Security 4; Red Hat Quay 3.

CVE-2026-19519
Unclassified
Aug 11, 2026
Medium5.9Vendor: HighMS Server

Medium [CVE-2026-6727] MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-6727
Windows Server
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-19391] Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives

Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Pen Drive Powered by Red Hat Lightspeed; Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat package: insights-core.

CVE-2026-19391
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.7Red Hat

Medium [CVE-2026-5304] Privilege escalation via malicious ACAP application installation

Privilege escalation via malicious ACAP application installation. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.

CVE-2026-5304
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-24330] Arbitrary File Read via malicious archive deployment

Arbitrary File Read via malicious archive deployment. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-434. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24330
Unclassified
Aug 11, 2026
Medium4.9Red Hat

Medium [CVE-2026-24329] Denial of Service via malformed payload injection by an authenticated administrative user.

Denial of Service via malformed payload injection by an authenticated administrative user. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-91. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24329
Unclassified
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability

.NET:.NET Core:.NET Security Feature Bypass Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62899
Unclassified
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability

.NET:.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62900
Unclassified
Aug 11, 2026
Low3.5Red Hat

Low [CVE-2026-73281] ssh-agent allows remote execution of local operations

ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73281
Red Hat Enterprise Linux
Aug 11, 2026
Low3.3Red Hat

Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding

Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.

CVE-2026-73071
Unclassified
Aug 11, 2026