Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-67301] Memory disclosure or denial of service via crafted RDP update orders
Memory disclosure or denial of service via crafted RDP update orders. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125.
Medium [CVE-2026-67290] Denial of Service via malformed media data
Denial of Service via malformed media data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser
Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.
Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection
Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.
Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation
Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.
Critical [CVE-2026-17566] pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool
pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-78.
Critical [CVE-2026-17349] pgAdmin 4: Unauthorized database credential access via adhoc server cloning
pgAdmin 4: Unauthorized database credential access via adhoc server cloning. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-639.
High [CVE-2026-65981] Authorization bypass allows session takeover via MOBILITY-TICKET session resume
Authorization bypass allows session takeover via MOBILITY-TICKET session resume. Red Hat rates this important (CVSS 7.1). Weakness: CWE-303.
High [CVE-2026-68770] Remote Code Execution via Security Control Bypass
Remote Code Execution via Security Control Bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-454. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-62959] Pre-authentication heap memory disclosure
Pre-authentication heap memory disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-908.
High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names
pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.
High [CVE-2026-18141] Authentication bypass in Event-Driven Ansible via forged HTTP header
Authentication bypass in Event-Driven Ansible via forged HTTP header. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/gateway-rhel9:1785435970, ansible-automation-platform-26/gateway-rhel9:1785780020. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-18446] Host confusion vulnerability via backslash in URI authority
Host confusion vulnerability via backslash in URI authority. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-18358] gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service
gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:54512 with package gnome-remote-desktop-0:49.3-4.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-11770] pre-auth LDAP filter injection in CleanAllRUV status check
pre-auth LDAP filter injection in CleanAllRUV status check. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-90. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing
pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-10079] Deploy-time policy enforcement and visibility bypass via label injection
Deploy-time policy enforcement and visibility bypass via label injection. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.
Medium [CVE-2026-18321] Denial of Service via buffer overflow in Zyfer refclock
Denial of Service via buffer overflow in Zyfer refclock. Red Hat rates this low (CVSS 4.7). Weakness: CWE-120.
Medium [CVE-2026-17350] pgAdmin 4: Permission bypass allows authenticated users to access restricted tools
pgAdmin 4: Permission bypass allows authenticated users to access restricted tools. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-425.
Medium [CVE-2026-17348] pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306.