Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-76036] Dawn in Google Chrome: Arbitrary code execution via crafted HTML page
Dawn in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120.
High [CVE-2026-75874] Sandbox escape in the Remote Settings Client component
Sandbox escape in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653.
High [CVE-2026-75838] Cross-Site Scripting via IN_PLACE sanitization
Cross-Site Scripting via IN_PLACE sanitization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Service Mesh 3; and 15 more. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Ansible Automation Platform 2; and 11 more.
Medium [CVE-2026-71084] Denial of Service via unauthenticated local access
Denial of Service via unauthenticated local access. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker
Denial of Service via network access by a low privileged attacker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-74989] Internally found bugs fixed in Firefox 154
Internally found bugs fixed in Firefox 154. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.
Medium [CVE-2026-74952] Privilege escalation in the Application Update component
Privilege escalation in the Application Update component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-250.
Medium [CVE-2026-74951] Clickjacking issue in Firefox for Android
Clickjacking issue in Firefox for Android. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1021.
Low [CVE-2026-74980] Clickjacking issue in the Downloads component in Firefox for Android
Clickjacking issue in the Downloads component in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1021.
Low [CVE-2026-74975] Spoofing issue in the Downloads component in Firefox for Android
Spoofing issue in the Downloads component in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-494.
High [CVE-2026-46345] Arbitrary file write via path traversal vulnerability
Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-19693] Arbitrary file write via symlink in archive
Arbitrary file write via symlink in archive. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Pipelines; OpenShift Service Mesh 3; and 13 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Ceph Storage 4; and 9 more.
Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing
Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-74579] fix mask build for partial field offload
fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal
Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.
Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation
Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.
Medium [CVE-2026-74578] algif_skcipher - force synchronous processing on trees without ctx->state
algif_skcipher - force synchronous processing on trees without ctx->state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1204. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Low [CVE-2026-74797] Denial of Service via malicious zip archives
Denial of Service via malicious zip archives. Red Hat rates this low (CVSS 3.1). Weakness: CWE-400.
Critical [CVE-2026-68457] use opener credentials for FSCTL mutations
use opener credentials for FSCTL mutations. Red Hat rates this important (CVSS 9.1). Weakness: CWE-270. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-73193] Arbitrary Code Execution on 32-bit Perl via Integer Wraparound
Arbitrary Code Execution on 32-bit Perl via Integer Wraparound. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: perl-dbi.