Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

89 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low1.1NETGEAR Updated

Low [CVE-2026-11734] buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. Affected products named by the advisory: MR70; MR90; MS70; MS90; and 4 more. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2.

CVE-2026-11734
Unclassified
Aug 11, 2026
Low1.1NETGEAR Updated

Low [CVE-2026-11733] buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device

A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. Affected products named by the advisory: RAX41; RAX41v2; RAX42; RAX42v2; and 4 more. Affected products named by the advisory: RAX43; RAX43v2; RAX49S; RAX50.

CVE-2026-11733
Unclassified
Aug 11, 2026
Low2.8Red Hat

Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff

Denial of Service via super-linear regular expression work in csv. Sniffer.sniff(). Red Hat rates this low (CVSS 2.8). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:54534 with package python3-10-main-3.10.21-1.hum1, python3-14-main-3.14.7-1.hum1, python3-13-main-3.13.15-1.hum1, python3-11-main-3.11.16-1.hum1.

CVE-2026-18503
Unclassified
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.

GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54508 with package cpio-main-2.15-10.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: cpio.

CVE-2026-66484
Red Hat Enterprise Linux
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-71391] off-by-one error via a malicious font file

off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.

CVE-2026-71391
Unclassified
Aug 10, 2026
Low3.9Red Hat

Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL

shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19411
Unclassified
Aug 10, 2026
Low3.7Red Hat

Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation

Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12372
Unclassified
Aug 9, 2026
Low2.3Red Hat

Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection

newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.

CVE-2026-61477
Unclassified
Aug 7, 2026
Low3.7NetApp

Low [CVE-2026-59848] Libssh Vulnerability in NetApp Products

Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59848
Unclassified
Aug 7, 2026
Low3.9NetApp

Low [CVE-2026-59846] Libssh Vulnerability in NetApp Products

Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59846
Unclassified
Aug 7, 2026
Low3.1NetApp

Low [CVE-2026-59849] Libssh Vulnerability in NetApp Products

Libssh versions 0.11.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59849
Unclassified
Aug 7, 2026
Low3.8Red Hat

Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision

Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.

CVE-2026-71326
Unclassified
Aug 6, 2026
Low3.7Red Hat

Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation

Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-57817
Unclassified
Aug 6, 2026
Low2.2Red Hat

Low [CVE-2026-18839] size_t underflow in singleOptionHelp

size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-18839
Unclassified
Aug 5, 2026
Low3.8Red Hat

Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration

Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70430
Unclassified
Aug 5, 2026
Low2.3Apache

Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVE-2026-68980
NiFi
Aug 3, 2026
Low2.5Red Hat

Low [CVE-2026-18739] Off-by-one in poptStuffArgs

Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18739
Unclassified
Aug 3, 2026
Low3.3Red Hat

Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply

NSS responder uninitialized heap disclosure in initgroups reply. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908.

CVE-2026-68744
Unclassified
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.

CVE-2026-66401
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67316
Unclassified
Aug 1, 2026