Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
High [CVE-2026-67305] Remote Code Execution via Heap Buffer Overflow in Clipboard Processing
Remote Code Execution via Heap Buffer Overflow in Clipboard Processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122.
High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names
pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.
High [CVE-2026-33630] c-ares Vulnerability in NetApp Products
C-ares versions higher than 1.32.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-39822] Golang Vulnerability in NetApp Products
Golang versions prior to 1.25.12, 1.26.0-0 prior to 1.26.5, and 1.27.0-0 prior to 1.27.0-rc.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-26143] Microsoft PowerShell Vulnerability in NetApp Products
Microsoft PowerShell versions 7.2.0-preview2 through 7.4.13, 7.5.0-preview1 through 7.5.4 and 7.6.0-preview1 through 7.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-40993] Spring Security Vulnerability in NetApp Products
Spring Security versions 7.0.0 prior to 7.0.6 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction
Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.
High [CVE-2026-18353] Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass
Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.
High [CVE-2026-47882] Spring Boot: When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud F…
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
High [CVE-2026-47858] Spring Boot: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applic…
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
High [CVE-2026-17986] Insufficient policy enforcement in Bluetooth
Insufficient policy enforcement in Bluetooth. Red Hat rates this low (CVSS 8.7). Weakness: CWE-346.
High [CVE-2026-17985] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 8.2). Weakness: CWE-653.
High [CVE-2026-17918] Use after free in Sync
Use after free in Sync. Red Hat rates this low (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-17896] Use after free in DevTools
Use after free in DevTools. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-825.
High [CVE-2026-17888] Insufficient validation of untrusted input in WebUI
Insufficient validation of untrusted input in WebUI. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1286.
High [CVE-2026-17884] Object lifecycle issue in WebRTC
Object lifecycle issue in WebRTC. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-1341.
High [CVE-2026-17887] Use after free in TabStrip
Use after free in TabStrip. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-17886] Use after free in Enterprise
Use after free in Enterprise. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-17881] Use after free in WebXR
Use after free in WebXR. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-190.