Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Red Hat

Medium [CVE-2026-19012] Authenticated denial of service via configuration entry

Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19012
Red Hat Enterprise Linux
Aug 7, 2026
Medium4.2Red Hat

Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API

Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19016
Red Hat Enterprise Linux
Aug 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges

Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.

CVE-2026-71852
Unclassified
Aug 7, 2026
Medium6.2Red Hat

Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems

Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.

CVE-2026-18938
Unclassified
Aug 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction

Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12261
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-56145] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.19.0 through 8.19.17, 9.3.0 through 9.3.6, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-56145
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-63144] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.19.0 through 8.19.18, 9.3.0 through 9.3.7, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63144
Unclassified
Aug 7, 2026
Medium6.5NetApp Updated

Medium [CVE-2026-63136] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.0.0 through 8.19.14, 9.0.0 through 9.2.8, and 9.3.0 through 9.3.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63136
Unclassified
Aug 7, 2026
Low2.3Red Hat

Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection

newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.

CVE-2026-61477
Unclassified
Aug 7, 2026
Critical9.3Sophos

Critical [CVE-2026-18367] privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

CVE-2026-18367
Unclassified
Aug 6, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium

Sandbox escape via out-of-bounds write in Chromium. Red Hat rates this important (CVSS 9). Weakness: CWE-787.

CVE-2026-19173
Unclassified
Aug 6, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-19155] Sandbox escape via use-after-free in Payments

Sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 9). Weakness: CWE-825.

CVE-2026-19155
Unclassified
Aug 6, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-19137] Google Chrome on Android: Sandbox escape via use after free in WebGL

Google Chrome on Android: Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825.

CVE-2026-19137
Unclassified
Aug 6, 2026
Critical9.6Red Hat

Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…

@nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Execution via Zip-Slip vulnerability in self-hosted remote cache. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.

CVE-2026-71476
Unclassified
Aug 6, 2026
Critical9.1Apache

Critical [CVE-2026-32327] bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem function

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVE-2026-32327
Unclassified
Aug 6, 2026
Critical9.1Apache

Critical [CVE-2026-34191] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

CVE-2026-34191
Unclassified
Aug 6, 2026
Critical9.8Red Hat

Critical [CVE-2026-5134] Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability

Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.

CVE-2026-5134
Unclassified
Aug 6, 2026
Critical9.1Apache

Critical [CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVE-2026-61466
Unclassified
Aug 6, 2026
Critical9.1Apache

Critical [CVE-2026-63687] Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVE-2026-63687
Unclassified
Aug 6, 2026
Critical9.1Apache

Critical [CVE-2026-65583] Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.

CVE-2026-65583
Unclassified
Aug 6, 2026