Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.1Red Hat

Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan

potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66807
Unclassified
Aug 14, 2026
Low3.5Red Hat

Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in

Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.

CVE-2026-55987
Unclassified
Aug 13, 2026
Low2.7Red Hat

Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API

Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.

CVE-2026-55984
Unclassified
Aug 13, 2026
Low0.0Red Hat

Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations

Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.

CVE-2026-73626
Unclassified
Aug 13, 2026
Low3.7Red Hat

Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass

Arbitrary code execution due to URI scheme bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-76. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.

CVE-2026-73492
Unclassified
Aug 12, 2026
Low3.7Red Hat

Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing

Cross-Site Scripting via malformed `javascript:` URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1289.

CVE-2026-73491
Unclassified
Aug 12, 2026
Low3.3GitLab

Low [CVE-2025-9486] GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.

CVE-2025-9486
Unclassified
Aug 12, 2026
Low3.5Red Hat

Low [CVE-2026-73281] ssh-agent allows remote execution of local operations

ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73281
Red Hat Enterprise Linux
Aug 11, 2026
Low3.3Red Hat

Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding

Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.

CVE-2026-73071
Unclassified
Aug 11, 2026
Low1.9NETGEAR Updated

Low [CVE-2026-11736] stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. Affected products named by the advisory: RAX20; RAX35v2; RAX41; RAX41v2; and 4 more. Affected products named by the advisory: RAX42; RAX42v2; RAX43; RAX43v2.

CVE-2026-11736
Unclassified
Aug 11, 2026
Low1.9NETGEAR Updated

Low [CVE-2026-11735] stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality

A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. Affected products named by the advisory: R7000; RAX20; RAX35v2; RAX41; and 4 more. Affected products named by the advisory: RAX41v2; RAX42; RAX42v2; RAX43.

CVE-2026-11735
Unclassified
Aug 11, 2026
Low1.1NETGEAR Updated

Low [CVE-2026-11734] buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. Affected products named by the advisory: MR70; MR90; MS70; MS90; and 4 more. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2.

CVE-2026-11734
Unclassified
Aug 11, 2026
Low1.1NETGEAR Updated

Low [CVE-2026-11733] buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device

A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2; and 4 more. Affected products named by the advisory: RAX43; RAX43v2; RAX49S; RAX50.

CVE-2026-11733
Unclassified
Aug 11, 2026
Low2.8Red Hat

Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff

Denial of Service via super-linear regular expression work in csv. Sniffer.sniff(). Red Hat rates this low (CVSS 2.8). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:54534 with package python3-10-main-3.10.21-1.hum1, python3-14-main-3.14.7-1.hum1, python3-13-main-3.13.15-1.hum1, python3-11-main-3.11.16-1.hum1.

CVE-2026-18503
Unclassified
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.

GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54508 with package cpio-main-2.15-10.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: cpio.

CVE-2026-66484
Red Hat Enterprise Linux
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-71391] off-by-one error via a malicious font file

off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.

CVE-2026-71391
Unclassified
Aug 10, 2026
Low3.9Red Hat

Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL

shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19411
Unclassified
Aug 10, 2026
Low3.7Red Hat

Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation

Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12372
Unclassified
Aug 9, 2026
Low2.3Red Hat

Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection

newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.

CVE-2026-61477
Unclassified
Aug 7, 2026
Low3.8Red Hat

Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision

Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.

CVE-2026-71326
Unclassified
Aug 6, 2026