Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Red Hat Updated

Medium [CVE-2026-59894] Arbitrary code execution via unescaped backslashes in generated snippets

Arbitrary code execution via unescaped backslashes in generated snippets. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.

CVE-2026-59894
Unclassified
Aug 17, 2026
Medium5.6Red Hat

Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service

Remote buffer overflow allows information disclosure or denial of service. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-120.

CVE-2026-19999
Unclassified
Aug 17, 2026
Medium6.3Red Hat

Medium [CVE-2026-19970] Remote heap-based buffer overflow vulnerability

Remote heap-based buffer overflow vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19970
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.4Red Hat

Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing

Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19969
Red Hat Enterprise Linux
Aug 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser

Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19968
Red Hat Enterprise Linux
Aug 17, 2026
Medium6.3Red Hat

Medium [CVE-2026-19967] Heap-based buffer overflow in file decompression

Heap-based buffer overflow in file decompression. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19967
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-74579] fix mask build for partial field offload

fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74579
Linux Kernel
Aug 17, 2026
Medium6.1Red Hat

Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal

Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.

CVE-2026-74796
Unclassified
Aug 16, 2026
Medium5.9Red Hat

Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation

Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.

CVE-2024-58375
Unclassified
Aug 16, 2026
Medium5.5Red Hat

Medium [CVE-2026-74578] algif_skcipher - force synchronous processing on trees without ctx->state

algif_skcipher - force synchronous processing on trees without ctx->state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1204. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74578
Linux Kernel
Aug 16, 2026
Medium4.3Apache

Medium [CVE-2026-73632] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73632
Struts
Aug 15, 2026
Medium4.3Apache

Medium [CVE-2026-73631] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73631
Struts
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72428] Fix stack slot index in nospec checks

Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72428
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path

Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72245
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup

Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72403
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename

fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-72190
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72292] Initialize KVM_S390_GET_CMMA_BITS memory

Initialize KVM_S390_GET_CMMA_BITS memory. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908.

CVE-2026-72292
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72454] Fix race in i3c_hci_addr_to_dev

Fix race in i3c_hci_addr_to_dev(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72454
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72025] Reject buffer reuse with different data length

Reject buffer reuse with different data length. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72025
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72396] Prevent reading uninitialized stack

Prevent reading uninitialized stack. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-72396
Linux Kernel
Aug 15, 2026