Complete feed
Security advisories & CVEs
89 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-11734] buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. Affected products named by the advisory: MR70; MR90; MS70; MS90; and 4 more. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2.
Low [CVE-2026-11733] buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2; and 4 more. Affected products named by the advisory: RAX43; RAX43v2; RAX49S; RAX50.
Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff
Denial of Service via super-linear regular expression work in csv. Sniffer.sniff(). Red Hat rates this low (CVSS 2.8). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:54534 with package python3-10-main-3.10.21-1.hum1, python3-14-main-3.14.7-1.hum1, python3-13-main-3.13.15-1.hum1, python3-11-main-3.11.16-1.hum1.
Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.
GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54508 with package cpio-main-2.15-10.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: cpio.
Low [CVE-2026-71391] off-by-one error via a malicious font file
off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.
Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL
shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation
Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.
Low [CVE-2026-59848] Libssh Vulnerability in NetApp Products
Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-59846] Libssh Vulnerability in NetApp Products
Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-59849] Libssh Vulnerability in NetApp Products
Libssh versions 0.11.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision
Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.
Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation
Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.
Low [CVE-2026-18839] size_t underflow in singleOptionHelp
size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration
Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.
Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.
Low [CVE-2026-18739] Off-by-one in poptStuffArgs
Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.
Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply
NSS responder uninitialized heap disclosure in initgroups reply. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908.
Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser
Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.
Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection
Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.