Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.1Red Hat Updated

High [CVE-2026-75147] Information disclosure or denial of service via crafted AV1 RTP packet

Information disclosure or denial of service via crafted AV1 RTP packet. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75147
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-75146] Information disclosure and denial of service via out-of-bounds read in DASH demuxer

Information disclosure and denial of service via out-of-bounds read in DASH demuxer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75146
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75144] Memory corruption via crafted Dirac data unit

Memory corruption via crafted Dirac data unit. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75144
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75142] Stack Buffer Overflow in MPEG-PS Muxer

Stack Buffer Overflow in MPEG-PS Muxer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75142
Unclassified
Aug 19, 2026
High7.5Cisco

High [CVE-2026-20320] Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20320
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-76233] Arbitrary command execution via gleam manager command injection

Arbitrary command execution via gleam manager command injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-76233
Unclassified
Aug 19, 2026
High8.2Red Hat Updated

High [CVE-2026-76222] Arbitrary file creation via path traversal in.gitmodules submodule names

Arbitrary file creation via path traversal in.gitmodules submodule names. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-76222
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-76221] Arbitrary code execution via config-name injection

Arbitrary code execution via config-name injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76221
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-76220] Arbitrary command execution via crafted kwargs

Arbitrary command execution via crafted kwargs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76220
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-76219] Arbitrary File Overwrite via `git read-tree` option injection

Arbitrary File Overwrite via `git read-tree` option injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76219
Unclassified
Aug 19, 2026
High7.5Red Hat Updated

High [CVE-2026-76218] Remote Code Execution via malicious Git hooks

Remote Code Execution via malicious Git hooks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76218
Unclassified
Aug 19, 2026
High7.5Red Hat

High [CVE-2020-37267] Information disclosure via unredacted logging of authorization tokens

Information disclosure via unredacted logging of authorization tokens. Red Hat rates this important (CVSS 7.5). Weakness: CWE-538.

CVE-2020-37267
Unclassified
Aug 19, 2026
High7.8Red Hat

High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution

Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.

CVE-2026-43961
Unclassified
Aug 19, 2026
High8.8NetScaler

High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19489
NetScaler Gateway
Aug 19, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html

unauthenticated remote memory leak via CockpitLang cookie in send_login_html. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-76235
Unclassified
Aug 19, 2026
High7.3Red Hat Updated

High [CVE-2026-58081] Heap-based buffer overflow in encoding modules

Heap-based buffer overflow in encoding modules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: php.

CVE-2026-58081
Red Hat Enterprise Linux
Aug 19, 2026
High7.6Atlassian Updated

High [CVE-2026-21584] Confluence: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.

CVE-2026-21584
Bamboo / Crowd / Fisheye
Aug 18, 2026
High8.8Atlassian

High [CVE-2026-21582] Confluence: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.

CVE-2026-21582
Bamboo / Crowd / Fisheye
Aug 18, 2026
High8.8Red Hat

High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.

Remote code execution via type confusion in crafted HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.

CVE-2026-76038
Unclassified
Aug 18, 2026
High7.4Red Hat

High [CVE-2026-76041] Information leak allows web origin policy bypass

Information leak allows web origin policy bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346.

CVE-2026-76041
Unclassified
Aug 18, 2026