Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-71391] off-by-one error via a malicious font file
off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.
Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL
shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation
Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-59848] Libssh Vulnerability in NetApp Products
Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-59846] Libssh Vulnerability in NetApp Products
Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-59849] Libssh Vulnerability in NetApp Products
Libssh versions 0.11.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-18839] size_t underflow in singleOptionHelp
size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.
Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser
Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.
Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation
Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.
Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Low [CVE-2026-18018] Inappropriate implementation in Updater
Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).
Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.
Low [CVE-2026-18010] Inappropriate implementation in Passwords
Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.
Low [CVE-2026-18007] Inappropriate implementation in Input
Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.
Low [CVE-2026-18004] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.
Low [CVE-2026-18001] Inappropriate implementation in WebGL
Inappropriate implementation in WebGL. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825.
Low [CVE-2026-18000] Insufficient policy enforcement in USB
Insufficient policy enforcement in USB. Red Hat rates this low (CVSS 2.8). Weakness: CWE-346.
Low [CVE-2026-17997] Inappropriate implementation in Passwords
Inappropriate implementation in Passwords. Red Hat rates this low (CVSS 2.4). Weakness: CWE-368.
Low [CVE-2026-17996] Inappropriate implementation in Browser
Inappropriate implementation in Browser. Red Hat rates this low (CVSS 3.9). Weakness: CWE-807.