Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat Updated

Medium [CVE-2026-76923] Denial of Service due to out-of-bounds read in Bluetooth HFP dissector

Denial of Service due to out-of-bounds read in Bluetooth HFP dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76923
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-76918] Denial of Service via SSH protocol dissector crash

Denial of Service via SSH protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76918
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-76917] Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector

Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76917
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-76880] Denial of Service via RRC protocol dissector out-of-bounds write

Denial of Service via RRC protocol dissector out-of-bounds write. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: wireshark.

CVE-2026-76880
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-76879] Denial of Service via C12.22 protocol dissector crash

Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76879
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-76889] Denial of Service via UMTS FP protocol dissector crash

Denial of Service via UMTS FP protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76889
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-76886] Denial of Service via C12.22 protocol dissector crash

Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.

CVE-2026-76886
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-76883] Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser

Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76883
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-76882] Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read

Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76882
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-76881] Denial of service via CMS protocol dissector crash

Denial of service via CMS protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76881
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-76827] UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)

UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering). Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-indexer-rhel9:1787688957, rhacm2/acm-search-indexer-rhel9:1787247085, rhacm2/acm-search-indexer-rhel9:1787250074, rhacm2/acm-search-indexer-rhel9:1787262474. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-76827
Unclassified
Aug 19, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-68554] Unauthorized actions or resource manipulation via STUN request modification

Unauthorized actions or resource manipulation via STUN request modification. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-354.

CVE-2026-68554
Unclassified
Aug 19, 2026
Medium5.3pfSense

Medium [CVE-2026-67189] pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.

CVE-2026-67189
pfSense PluspfSense CE
Aug 19, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-69159] Out-of-bounds read leads to denial of service and information disclosure

Out-of-bounds read leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-69159
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-63652] Denial of Service and heap corruption via malformed RDP audio PDU

Denial of Service and heap corruption via malformed RDP audio PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-63652
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation

Denial of Service via ADPCM frame size calculation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-63117
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription

annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-volsync-addon-controller-rhel9:1787266360, rhacm2/acm-volsync-addon-controller-rhel9:1787683560, rhacm2/acm-volsync-addon-controller-rhel9:1787266556, rhacm2/acm-volsync-addon-controller-rhel9:1787266564. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-18874
Unclassified
Aug 19, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-55648] Integer overflow allows out-of-bounds read via malicious RDP server

Integer overflow allows out-of-bounds read via malicious RDP server. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55648
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-55564] Out-of-bounds read in glyph cache leads to denial of service and information disclosure

Out-of-bounds read in glyph cache leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55564
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.8Red Hat Updated

Medium [CVE-2026-75145] Out-of-bounds memory access due to integer narrowing conversion

Out-of-bounds memory access due to integer narrowing conversion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75145
Unclassified
Aug 19, 2026