Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5245 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low2.9Linux

Low [CVE-2026-0992] Denial of Service via crafted XML catalogs

Denial of Service via crafted XML catalogs. Red Hat rates this low (CVSS 2.9). Weakness: CWE-400. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0992
Unclassified
Jan 15, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2025-70968] Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE()

Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-416. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70968
Unclassified
Jan 14, 2026
High8.1Vendor: LowLinux

High [CVE-2026-0861] Integer overflow in memalign leads to heap corruption

Integer overflow in memalign leads to heap corruption. Red Hat rates this low (CVSS 8.1). Weakness: CWE-190. Affected package(s): glibc-main, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073, rhui5/haproxy-rhel9:1773672059. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-0861
Unclassified
Jan 14, 2026
High7.4Linux

High [CVE-2026-22859] FreeRDP heap-buffer-overflow

FreeRDP heap-buffer-overflow. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:4439 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-22859
Red Hat Enterprise Linux
Jan 14, 2026
High7.4Linux

High [CVE-2026-22858] FreeRDP global-buffer-overflow

FreeRDP global-buffer-overflow. Red Hat rates this important (CVSS 7.4). Weakness: CWE-787. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:4439 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-22858
Red Hat Enterprise Linux
Jan 14, 2026
High8.1Vendor: MediumLinux

High [CVE-2026-22856] FreeRDP heap-use-after-free

FreeRDP heap-use-after-free. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-416. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-22856
Unclassified
Jan 14, 2026
High8.1Vendor: MediumLinux

High [CVE-2026-22854] FreeRDP heap-buffer-overflow

FreeRDP heap-buffer-overflow. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-22854
Unclassified
Jan 14, 2026
High8.1Linux

High [CVE-2026-22853] FreeRDP heap-buffer-overflow

FreeRDP heap-buffer-overflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19033 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6.

CVE-2026-22853
Red Hat Enterprise Linux
Jan 14, 2026
High8.6Linux

High [CVE-2026-0532] Arbitrary file disclosure via specially crafted connector configuration

Arbitrary file disclosure via specially crafted connector configuration. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift distributed tracing 3.

CVE-2026-0532
Unclassified
Jan 14, 2026
High7.1Vendor: MediumLinux

High [CVE-2025-71116] make decode_pool() more resilient against corrupted osdmaps

make decode_pool() more resilient against corrupted osdmaps. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2025-71116
Unclassified
Jan 14, 2026
Medium5.6Linux

Medium [CVE-2026-22852] FreeRDP heap-buffer-overflow

FreeRDP heap-buffer-overflow. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-787. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-22852
Unclassified
Jan 14, 2026
Medium6.5Linux

Medium [CVE-2025-14242] Denial of service via integer overflow in ls command parameter parsing

Denial of service via integer overflow in ls command parameter parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected package(s): vsftpd. Resolved in Red Hat advisory RHSA-2026:4470 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2025-14242
Unclassified
Jan 14, 2026
Medium4.4Vendor: LowLinux

Medium [CVE-2025-71117] Linux kernel: Denial of Service via deadlock in block layer sysfs store callbacks

Linux kernel: Denial of Service via deadlock in block layer sysfs store callbacks. Red Hat rates this low (CVSS 4.4). Weakness: CWE-833. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-71117
Unclassified
Jan 14, 2026
Low3.7Linux

Low [CVE-2026-22036] Denial of Service via excessive decompression steps

Denial of Service via excessive decompression steps. Red Hat rates this low (CVSS 3.7). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-22036
Unclassified
Jan 14, 2026
High7.5Linux

High [CVE-2026-0891] Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147

Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-0891
Red Hat Enterprise Linux
Jan 13, 2026
High7.5Linux

High [CVE-2026-0882] Use-after-free in the IPC component

Use-after-free in the IPC component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-0882
Red Hat Enterprise Linux
Jan 13, 2026
High7.5Linux

High [CVE-2026-0881] Sandbox escape in the Messaging System component

Sandbox escape in the Messaging System component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0881
Unclassified
Jan 13, 2026
High7.5Linux

High [CVE-2026-0879] Sandbox escape due to incorrect boundary conditions in the Graphics component

Sandbox escape due to incorrect boundary conditions in the Graphics component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-0879
Red Hat Enterprise Linux
Jan 13, 2026
High7.5Linux

High [CVE-2026-0880] Sandbox escape due to integer overflow in the Graphics component

Sandbox escape due to integer overflow in the Graphics component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-0880
Red Hat Enterprise Linux
Jan 13, 2026
High7.5Linux

High [CVE-2026-0878] Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-0878
Red Hat Enterprise Linux
Jan 13, 2026