Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

7850 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat Updated

High [CVE-2026-74939] Privilege escalation in the DOM: Navigation component

Privilege escalation in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74939
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74934] Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74934
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74936] Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74936
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74935] Privilege escalation in the DOM: Networking component

Privilege escalation in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74935
Unclassified
Aug 18, 2026
High7.3Red Hat Updated

High [CVE-2026-75838] Cross-Site Scripting via IN_PLACE sanitization

Cross-Site Scripting via IN_PLACE sanitization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Service Mesh 3; and 15 more. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Ansible Automation Platform 2; and 11 more.

CVE-2026-75838
Unclassified
Aug 18, 2026
High7.5Vendor: MediumRed Hat Updated

High [CVE-2026-70906] Improve font loading (2026-08 Security Update)

Improve font loading (2026-08 Security Update). Red Hat rates this moderate (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:55799 with package java-25-openjdk-portable, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-70906
Unclassified
Aug 18, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-71084] Denial of Service via unauthenticated local access

Denial of Service via unauthenticated local access. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.

CVE-2026-71084
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker

Denial of Service via network access by a low privileged attacker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.

CVE-2026-71079
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.8Red Hat

Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU

Information disclosure via uninitialized resource in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-824.

CVE-2026-76042
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-16732] Request spoofing via numeric trustProxy configuration

Request spoofing via numeric trustProxy configuration. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-16732
Unclassified
Aug 18, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-18504] Schema validation bypass via root primitive coercion mismatch

Schema validation bypass via root primitive coercion mismatch. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-18504
Unclassified
Aug 18, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-49452] CSS Injection via Presentational Hints

CSS Injection via Presentational Hints. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-79.

CVE-2026-49452
Unclassified
Aug 18, 2026
Medium6.5Vendor: HighRed Hat Updated

Medium [CVE-2026-66781] IPsec PSK stored cleartext in Submariner CR spec

IPsec PSK stored cleartext in Submariner CR spec. Red Hat rates this important (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66781
Unclassified
Aug 18, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-75485] cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials

cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-532. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-must-gather-rhel9:1787238730, rhacm2/acm-must-gather-rhel9:1787263322, rhacm2/acm-must-gather-rhel9:1787260453, rhacm2/acm-must-gather-rhel9:1787228698. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-75485
Unclassified
Aug 18, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-73834] embedded Secret data in ACM wrapper CRs collected without redaction

embedded Secret data in ACM wrapper CRs collected without redaction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-must-gather-rhel9:1787238730, rhacm2/acm-must-gather-rhel9:1787263322, rhacm2/acm-must-gather-rhel9:1787260453, rhacm2/acm-must-gather-rhel9:1787228698. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-73834
Unclassified
Aug 18, 2026
Medium6.3Red Hat

Medium [CVE-2026-75032] Out-of-bounds read in AVRCP parse_media_element and parse_media_folder

Out-of-bounds read in AVRCP parse_media_element and parse_media_folder. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-75032
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74989] Internally found bugs fixed in Firefox 154

Internally found bugs fixed in Firefox 154. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.

CVE-2026-74989
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74966] Information disclosure in the Form Autofill component

Information disclosure in the Form Autofill component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-359.

CVE-2026-74966
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74968] Site isolation issue in the Graphics: WebRender component

Site isolation issue in the Graphics: WebRender component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501.

CVE-2026-74968
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74970] Site isolation issue in the Graphics component

Site isolation issue in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501.

CVE-2026-74970
Unclassified
Aug 18, 2026