Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.3Red Hat

Low [CVE-2026-71391] off-by-one error via a malicious font file

off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.

CVE-2026-71391
Unclassified
Aug 10, 2026
Low3.9Red Hat

Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL

shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19411
Unclassified
Aug 10, 2026
Low3.7Red Hat

Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation

Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12372
Unclassified
Aug 9, 2026
Low3.7NetApp

Low [CVE-2026-59848] Libssh Vulnerability in NetApp Products

Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59848
Unclassified
Aug 7, 2026
Low3.9NetApp

Low [CVE-2026-59846] Libssh Vulnerability in NetApp Products

Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59846
Unclassified
Aug 7, 2026
Low3.1NetApp

Low [CVE-2026-59849] Libssh Vulnerability in NetApp Products

Libssh versions 0.11.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59849
Unclassified
Aug 7, 2026
Low2.2Red Hat

Low [CVE-2026-18839] size_t underflow in singleOptionHelp

size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-18839
Unclassified
Aug 5, 2026
Low2.3Apache

Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVE-2026-68980
NiFi
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.

CVE-2026-66401
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.

CVE-2026-67294
Unclassified
Aug 1, 2026
Low3.3VMware

Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59326
Tanzu / Spring
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18018] Inappropriate implementation in Updater

Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).

CVE-2026-18018
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools

Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.

CVE-2026-18014
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18010] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.

CVE-2026-18010
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18007] Inappropriate implementation in Input

Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.

CVE-2026-18007
Unclassified
Jul 30, 2026
Low3.2Red Hat

Low [CVE-2026-18004] Insufficient policy enforcement in Speech

Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.

CVE-2026-18004
Unclassified
Jul 30, 2026
Low3.1Red Hat

Low [CVE-2026-18001] Inappropriate implementation in WebGL

Inappropriate implementation in WebGL. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825.

CVE-2026-18001
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18000] Insufficient policy enforcement in USB

Insufficient policy enforcement in USB. Red Hat rates this low (CVSS 2.8). Weakness: CWE-346.

CVE-2026-18000
Unclassified
Jul 30, 2026
Low2.4Red Hat

Low [CVE-2026-17997] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low (CVSS 2.4). Weakness: CWE-368.

CVE-2026-17997
Unclassified
Jul 30, 2026
Low3.9Red Hat

Low [CVE-2026-17996] Inappropriate implementation in Browser

Inappropriate implementation in Browser. Red Hat rates this low (CVSS 3.9). Weakness: CWE-807.

CVE-2026-17996
Unclassified
Jul 30, 2026