Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3243 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat Updated

Medium [CVE-2026-74592] Instantiate file_truncate and path_truncate hooks

Instantiate file_truncate and path_truncate hooks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-222. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74592
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74605] Use children field for rcu head and add memory barriers

Use children field for rcu head and add memory barriers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74605
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74667] reset the MAC header on the packet-socket transmit path

reset the MAC header on the packet-socket transmit path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74667
Linux Kernel
Aug 22, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74698] fix BQL reset on SQ re-activation

fix BQL reset on SQ re-activation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74698
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74725] fix tx_hang_reset use-after-free on device removal

fix tx_hang_reset use-after-free on device removal. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74725
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74685] (ltc4282) Clamp negative current limits

(ltc4282) Clamp negative current limits. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.

CVE-2026-74685
Unclassified
Aug 22, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74708] validate launch-time metadata size

validate launch-time metadata size. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74708
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74658] Prevent robust futex exit race some more

Prevent robust futex exit race some more. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74658
Linux Kernel
Aug 22, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74636] Fix race between update_event_fields and, event_define_fields

Fix race between update_event_fields and, event_define_fields. Red Hat rates this low (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74636
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74627] prevent net-iov / page mixing

prevent net-iov / page mixing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-74627
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74687] prevent timer rearm during teardown

prevent timer rearm during teardown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-74687
Unclassified
Aug 22, 2026
Low2.5Red Hat

Low [CVE-2026-71514] Information disclosure via path traversal in CrubadanCorpusReader

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who controls a corpus package can disclose file contents outside the corpus root through lang_freq, limited to paths ending in -3grams.txt whose contents parse as token count lines. A flaw was found in NLTK. This occurs because a specially crafted input can bypass security checks, leading to unauthorized information disclosure. This Low impact vulnerability in NLTK's CrubadanCorpusReader allows for limited information disclosure via path traversal. Exploitation requires an attacker to provide a specially crafted corpus package, restricting the attack surface. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-22. Red Hat lists Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI) as not affected.

CVE-2026-71514
Unclassified
Aug 22, 2026
Critical9.1Vendor: MediumRed Hat

Critical [CVE-2026-66786] ipsec.conf stanza injection via remote-supplied CableName and Subnets

ipsec.conf stanza injection via remote-supplied CableName and Subnets. Red Hat rates this moderate (CVSS 9.1). Weakness: CWE-94.

CVE-2026-66786
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-63125] Incus vulnerable to root RCE via image backup.yaml symlink

Incus vulnerable to root RCE via image backup.yaml symlink. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.

CVE-2026-63125
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62941] Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-367.

CVE-2026-62941
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62940] Incus has a project restriction bypass via instance migration config override

Incus has a project restriction bypass via instance migration config override. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.

CVE-2026-62940
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62867] Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution

Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.

CVE-2026-62867
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48769] Incus has an arbitrary file write on its client due to trusted image hash

Incus has an arbitrary file write on its client due to trusted image hash. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-345.

CVE-2026-48769
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48755] Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Incus has an argument injection in backup compression algorithm leading to AFW and ACE. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.

CVE-2026-48755
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48753] Incus has an arbitrary file write via path traversal in S3 multipart upload

Incus has an arbitrary file write via path traversal in S3 multipart upload. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-22.

CVE-2026-48753
Unclassified
Aug 21, 2026