Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80553] Cancel existing workqueues

Cancel existing workqueues. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80553
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80558] Avoid using invalid osd indices from primary_temp

Avoid using invalid osd indices from primary_temp. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80558
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80571] papr-phy-attest - validate cmd.length, plug mem leak

papr-phy-attest - validate cmd.length, plug mem leak. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80571
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80582] Check VMA boundaries for PMD mappings

Check VMA boundaries for PMD mappings. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-80582
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74737] Fix port_id extraction from SRC TAG

Fix port_id extraction from SRC TAG. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74737
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80584] validate user buffer length in SNMP and ARP query ioctls

validate user buffer length in SNMP and ARP query ioctls. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80584
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80521] Unlink scc_entry in unix_del_edge

Unlink scc_entry in unix_del_edge(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-80521
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74746] publish GC-visible tuple last

publish GC-visible tuple last. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74746
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80540] Fix UVD decode image min size calculation

Fix UVD decode image min size calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.

CVE-2026-80540
Unclassified
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80589] stop the timeout timer when releasing a never added disk

stop the timeout timer when releasing a never added disk. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80589
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80528] avoid fs reclaim while using current->journal_info

avoid fs reclaim while using current->journal_info. Red Hat rates this moderate (CVSS 7). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80528
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80552] Ensure index for read/write regions are within range

Ensure index for read/write regions are within range. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80552
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80561] fix multiple unsafe decodes in decode_locker

fix multiple unsafe decodes in decode_locker(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80561
Linux Kernel
Aug 26, 2026
High7.7Red Hat Updated

High [CVE-2026-57171] Arbitrary file write via path traversal in author generate commands

Arbitrary file write via path traversal in author generate commands. Red Hat rates this important (CVSS 7.7). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-57171
Unclassified
Aug 25, 2026
High7.8Red Hat Updated

High [CVE-2026-57170] Arbitrary code execution via Server-Side Template Injection

Arbitrary code execution via Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.

CVE-2026-57170
Unclassified
Aug 25, 2026
High8.1Red Hat Updated

High [CVE-2026-52776] Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0

Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1289. Affected product named by the advisory: File Integrity Operator.

CVE-2026-52776
Unclassified
Aug 25, 2026
High7.8Red Hat Updated

High [CVE-2026-54757] Remote Code Execution via Server-Side Template Injection

Remote Code Execution via Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.

CVE-2026-54757
Unclassified
Aug 25, 2026
High7.4VMware Updated

High [CVE-2026-41707] Spring Security: Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwt…

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.

CVE-2026-41707
Tanzu / Spring
Aug 25, 2026
High7.5Red Hat Updated

High [CVE-2026-16645] Unauthorized access due to missing authorization

Unauthorized access due to missing authorization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-425.

CVE-2026-16645
Unclassified
Aug 25, 2026
High7.5Apache Updated

High [CVE-2026-68763] Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVE-2026-68763
Tomcat
Aug 25, 2026