Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.7Red Hat

High [CVE-2026-11425] Stored cross-site scripting allows administrator account takeover

Stored cross-site scripting allows administrator account takeover. Red Hat rates this important (CVSS 7.7). Weakness: CWE-79.

CVE-2026-11425
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-19113] Unauthenticated denial of service via unbounded request body processing

Unauthenticated denial of service via unbounded request body processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-19113
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-15972] Denial of Service via unbounded external gRPC connection acceptance

Denial of Service via unbounded external gRPC connection acceptance. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-15972
Red Hat Enterprise Linux
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-65819] Remote Denial of Service via crafted packet processing

Remote Denial of Service via crafted packet processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805.

CVE-2026-65819
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service

Uncontrolled resource consumption leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-19015
Unclassified
Aug 7, 2026
High7.1Red Hat

High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution

Arbitrary file read/write via symbolic link resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71556
Unclassified
Aug 7, 2026
High7.5Cisco PoC reported

High [CVE-2026-20337 +6] ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: - The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows. - The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac. - Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted.

CVE-2026-20337CVE-2026-20338CVE-2026-20339+4
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die

root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 5 more.

CVE-2026-15816
Unclassified
Aug 7, 2026
High7.5Apache

High [CVE-2026-71559] Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

CVE-2026-71559
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets

codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.

CVE-2025-63235
Unclassified
Aug 7, 2026
High7.7NetApp

High [CVE-2026-66035] Libssh2 Vulnerability in NetApp Products

Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-66035
Unclassified
Aug 7, 2026
High7.8NetApp

High [CVE-2026-64531] Linux Kernel Vulnerability in NetApp Products

Certain Linux kernel versions are susceptible to a vulnerability referred to as OVSwrap which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-64531
Unclassified
Aug 7, 2026
High8.7NetApp

High [CVE-2026-66033] Libssh2 Vulnerability in NetApp Products

Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-66033
ONTAPActive IQ Unified ManagerONTAP Select
Aug 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-46405] Denial of Service from unaccessible token accumulation in Kerberos authentication.

Denial of Service from unaccessible token accumulation in Kerberos authentication. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-46405
Unclassified
Aug 7, 2026
Medium4.4Red Hat

Medium [CVE-2026-46358] Authentication material disclosure via incorrect audit log redaction

Authentication material disclosure via incorrect audit log redaction. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-312.

CVE-2026-46358
Unclassified
Aug 7, 2026
Medium5.5SonicWall

Medium [CVE-2026-66151] Global VPN Client: SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec…

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

CVE-2026-66151
SSL-VPN & Clients
Aug 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-71870] Denial of Service via crafted PDF with large /ToUnicode streams

Denial of Service via crafted PDF with large /ToUnicode streams. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.

CVE-2026-71870
Unclassified
Aug 7, 2026
Medium4.2Red Hat

Medium [CVE-2026-15970] Authorization bypass via custom public listener

Authorization bypass via custom public listener. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-551. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-15970
Red Hat Enterprise Linux
Aug 7, 2026
Medium6.8Red Hat

Medium [CVE-2026-19017] Sensitive secret exfiltration via partial arbitrary file read

Sensitive secret exfiltration via partial arbitrary file read. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19017
Red Hat Enterprise Linux
Aug 7, 2026
Medium6.5Red Hat

Medium [CVE-2026-19014] Denial of Service via uncontrolled resource consumption in Connect authorization endpoint

Denial of Service via uncontrolled resource consumption in Connect authorization endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19014
Red Hat Enterprise Linux
Aug 7, 2026