Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-64572] free fib_alias with kfree_rcu on insert error path
free fib_alias with kfree_rcu() on insert error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67863] Denial of Service via use-after-free vulnerability
Denial of Service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-64577] check skb_pull_data return in gtp1u_send_echo_resp
check skb_pull_data() return in gtp1u_send_echo_resp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.
High [CVE-2026-64573] fix NVM tag length underflow in TLV parser
fix NVM tag length underflow in TLV parser. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap
Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic
Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.
High [CVE-2026-6837] post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
High [CVE-2026-67855] Denial of Service via heap use-after-free
Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function
Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server
Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67859] Denial of Service via Discovery/LDS handling
Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67862] Denial of Service via buffer-overflow
Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing
don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.
High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component
Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path
Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.
High [CVE-2026-68981] Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.
High [CVE-2026-62354] Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.
High [CVE-2026-12852] Bouncy Castle for Java: Denial of Service via MLS wire decoder
Bouncy Castle for Java: Denial of Service via MLS wire decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.
High [CVE-2026-58062] Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
High [CVE-2026-59650] Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value
Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325.