Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.4Red Hat

High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI

Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.

CVE-2026-8763
Red Hat Enterprise Linux
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-67305] Remote Code Execution via Heap Buffer Overflow in Clipboard Processing

Remote Code Execution via Heap Buffer Overflow in Clipboard Processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122.

CVE-2026-67305
Unclassified
Aug 1, 2026
High8.8Red Hat

High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names

pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.

CVE-2026-17346
Unclassified
Jul 31, 2026
High7.5NetApp

High [CVE-2026-33630] c-ares Vulnerability in NetApp Products

C-ares versions higher than 1.32.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-33630
Unclassified
Jul 31, 2026
High7.8NetApp

High [CVE-2026-39822] Golang Vulnerability in NetApp Products

Golang versions prior to 1.25.12, 1.26.0-0 prior to 1.26.5, and 1.27.0-0 prior to 1.27.0-rc.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-39822
Unclassified
Jul 31, 2026
High7.8NetApp

High [CVE-2026-26143] Microsoft PowerShell Vulnerability in NetApp Products

Microsoft PowerShell versions 7.2.0-preview2 through 7.4.13, 7.5.0-preview1 through 7.5.4 and 7.6.0-preview1 through 7.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-26143
Unclassified
Jul 31, 2026
High7.3NetApp

High [CVE-2026-40993] Spring Security Vulnerability in NetApp Products

Spring Security versions 7.0.0 prior to 7.0.6 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40993
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction

Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.

CVE-2026-12932
Unclassified
Jul 30, 2026
High8.2Red Hat

High [CVE-2026-18353] Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass

Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.

CVE-2026-18353
Unclassified
Jul 30, 2026
High8.3VMware

High [CVE-2026-47882] Spring Boot: When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud F…

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47882
Tanzu / Spring
Jul 30, 2026
High8.0VMware

High [CVE-2026-47858] Spring Boot: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applic…

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47858
Tanzu / Spring
Jul 30, 2026
High8.7Vendor: LowRed Hat

High [CVE-2026-17986] Insufficient policy enforcement in Bluetooth

Insufficient policy enforcement in Bluetooth. Red Hat rates this low (CVSS 8.7). Weakness: CWE-346.

CVE-2026-17986
Unclassified
Jul 30, 2026
High8.2Vendor: LowRed Hat

High [CVE-2026-17985] Insufficient policy enforcement in Speech

Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 8.2). Weakness: CWE-653.

CVE-2026-17985
Unclassified
Jul 30, 2026
High8.8Vendor: LowRed Hat

High [CVE-2026-17918] Use after free in Sync

Use after free in Sync. Red Hat rates this low (CVSS 8.8). Weakness: CWE-825.

CVE-2026-17918
Unclassified
Jul 30, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-17896] Use after free in DevTools

Use after free in DevTools. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-825.

CVE-2026-17896
Unclassified
Jul 30, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-17888] Insufficient validation of untrusted input in WebUI

Insufficient validation of untrusted input in WebUI. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1286.

CVE-2026-17888
Unclassified
Jul 30, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-17884] Object lifecycle issue in WebRTC

Object lifecycle issue in WebRTC. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-1341.

CVE-2026-17884
Unclassified
Jul 30, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-17887] Use after free in TabStrip

Use after free in TabStrip. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825.

CVE-2026-17887
Unclassified
Jul 30, 2026
High8.8Vendor: MediumRed Hat

High [CVE-2026-17886] Use after free in Enterprise

Use after free in Enterprise. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-825.

CVE-2026-17886
Unclassified
Jul 30, 2026
High8.8Vendor: MediumRed Hat

High [CVE-2026-17881] Use after free in WebXR

Use after free in WebXR. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-190.

CVE-2026-17881
Unclassified
Jul 30, 2026