VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
4892 advisories across 32 monitored vendors.
Memory corruption vulnerability via Double-Free/Use-After-Free. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
vibrantlabsai RAGAS: vibrantlabsai RAGAS: Server-Side Request Forgery via retrieved_contexts argument manipulation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width. Red Hat rates this moderate (CVSS 5). Weakness: CWE-131. Affected package(s): glibc, insights-proxy/insights-proxy-container-rhel9:1782890503, glibc-main. Resolved in Red Hat advisory RHSA-2026:33170 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Information disclosure or denial of service via ungetwc function with specific wide character encodings. Red Hat rates this moderate (CVSS 5). Weakness: CWE-125. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:12740 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Incorrect file installation due to improper archive handling. Red Hat rates this moderate (CVSS 5). Weakness: CWE-1287. Affected package(s): python-pip-main. Resolved in Red Hat advisory RHSA-2026:20074 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
GNU sed TOCTOU race condition. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-367. Affected package(s): sed-main. Resolved in Red Hat advisory RHSA-2026:10995 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Arbitrary code execution via injected protobuf definition type fields. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhdh/rhdh-hub-rhel9:1779841586, rhdh/rhdh-hub-rhel9:1781187342, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, rhoai/odh-dashboard-rhel9:1780467029. Resolved in Red Hat advisory RHSA-2026:21338 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 5 more.
Server-Side Template Injection via expression execution bypass. Red Hat rates this important (CVSS 8.5). Weakness: CWE-917. Affected package(s): devspaces/openvsx-rhel9:1779528224, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat Fuse 7; Red Hat Single Sign-On 7.
Server-Side Template Injection via security bypass in expression execution. Red Hat rates this important (CVSS 8.5). Weakness: CWE-917. Affected package(s): devspaces/openvsx-rhel9:1779528224, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat Fuse 7; Red Hat Single Sign-On 7.
cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Information disclosure of preshared API key via playground endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15.
mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend. Red Hat rates this important (CVSS 7.4). Weakness: CWE-287. Affected package(s): openshift4/ose-haproxy-router-rhel9:1781552170, openshift4/ose-haproxy-router-rhel9:1781643967, openshift4/ose-haproxy-router-rhel9:1781639027. Resolved in Red Hat advisory RHSA-2026:27063 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22; Red Hat OpenShift Container Platform 4.19; and 5 more.
Privilege Escalation via improper privilege management. Red Hat rates this important (CVSS 7). Weakness: CWE-273. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Denial of Service via unauthenticated root token generation or rekey operations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.
Information disclosure of authentication tokens via incorrect header handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.
Denial of Service due to unauthorized secret deletion via policy bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.
Denial of service via stack buffer overflow during QUIC handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): samba, ngtcp2-main. Resolved in Red Hat advisory RHSA-2026:22963 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images.
APCB SMM driver: kernel: linux-firmware: AMD APCB SMM driver: Arbitrary Code Execution via incorrect boot service use. Red Hat rates this important (CVSS 7.5). Weakness: CWE-648. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.
path traversal via the.install field. Red Hat rates this important (CVSS 7.1). Weakness: CWE-24. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Use-after-free vulnerability in extended attribute handling. Red Hat rates this important (CVSS 7.4). Weakness: CWE-805. Affected package(s): rsync, rhcos, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:25044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 17 more.