VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4209 advisories across 32 monitored vendors.
Arbitrary XML node injection via crafted processing instructions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. Affected package(s): rhdh/rhdh-hub-rhel9:1781187342. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`).
Directory traversal allows arbitrary file access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary XML markup injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. Affected package(s): rhdh/rhdh-hub-rhel9:1779841586, rhdh/rhdh-hub-rhel9:1781187342, openshift4/ose-agent-installer-ui-rhel9:1779864090, openshift4/ose-agent-installer-ui-rhel9:1779252093. Resolved in Red Hat advisory RHSA-2026:21703 — update the affected packages (`sudo dnf update`).
@xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): rhdh/rhdh-hub-rhel9:1781187342. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`).
@xmldom/xmldom: xmldom: Arbitrary XML Node Injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. Affected package(s): rhdh/rhdh-hub-rhel9:1781187342. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`).
Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications. Red Hat rates this important (CVSS 7.1). Weakness: CWE-693. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
"Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): rhcos, kernel, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`).
Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`).
Cross-site scripting due to incorrect script tag escaping. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1289. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`).
ReverseProxy forwards hidden query parameters, potentially bypassing security controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-472. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`).
heap use-after-free in libblkid nested partition probing. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-416. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:26573 — update the affected packages (`sudo dnf update`).
Regular Expression Denial of Service (ReDoS) via crafted Markdown input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Apache::Session::Generate::ModUniqueId: Perl: mod_unique_id: Apache HTTP Server: Apache::Session::Generate::ModUniqueId: Session ID predictability allows unauthorized access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
ensure safe access to master conntrack. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`).
validate bsscfg indices in IF events. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`).
fix out-of-bounds read in cifs_sanitize_prepath. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34911 — update the affected packages (`sudo dnf update`).
Fix RSS context delete logic. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-772. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`).
fix possible double mmput() in do_procmap_query(). Red Hat rates this important (CVSS 7). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
fix potential race in tcp_v6_syn_recv_sock(). Red Hat rates this important (CVSS 7). Weakness: CWE-821. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`).
don't return non-matching entry on expiry. Red Hat rates this important (CVSS 8.1). Weakness: CWE-480. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.