Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.4GitLab Updated

Medium [CVE-2026-4398] Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.

CVE-2026-4398
Unclassified
Aug 27, 2026
Medium6.8VMware Updated

Medium [CVE-2026-59272] RabbitMQ: Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exp…

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0

CVE-2026-59272
Tanzu / Spring
Aug 27, 2026
Medium4.3VMware Updated

Medium [CVE-2026-59280] Spring Framework: Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a cont…

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 5.2.25.RELEASE and earlier

CVE-2026-59280
Tanzu / Spring
Aug 27, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-81668] Cross-tenant Content View Filter rule access and modification via unauthorized parent filter lookup

Cross-tenant Content View Filter rule access and modification via unauthorized parent filter lookup. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-639. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-81668
Unclassified
Aug 27, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-81658] Cross-tenant disclosure of template revisions via unauthorized audit lookup

Cross-tenant disclosure of template revisions via unauthorized audit lookup. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-81658
Unclassified
Aug 27, 2026
Medium5.9Red Hat Updated

Medium [CVE-2026-80489] Non-progress DoS in SHIFT_JISX0213 -> UCS-4 conversion state

Non-progress DoS in SHIFT_JISX0213 -> UCS-4 conversion state. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: glibc.

CVE-2026-80489
Red Hat Enterprise Linux
Aug 27, 2026
Medium5.3VMware Updated

Medium [CVE-2026-59271] RabbitMQ: When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thr…

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0

CVE-2026-59271
Tanzu / Spring
Aug 27, 2026
Medium6.1VMware Updated

Medium [CVE-2026-47887] Spring Framework: Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a…

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47887
Tanzu / Spring
Aug 27, 2026
Medium6.1VMware Updated

Medium [CVE-2026-47883] Spring Framework: UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns.

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47883
Tanzu / Spring
Aug 27, 2026
Medium4.9VMware Updated

Medium [CVE-2026-47894] Spring Cloud: Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the config…

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 3.1.14 and earlier

CVE-2026-47894
Tanzu / Spring
Aug 27, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-38350] Integer overflow leads to Denial of Service

Integer overflow leads to Denial of Service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38350
Unclassified
Aug 27, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-38347] Heap overflow vulnerability leads to Denial of Service

Heap overflow vulnerability leads to Denial of Service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38347
Unclassified
Aug 27, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-38348] Denial of Service via crafted image file due to integer overflow

Denial of Service via crafted image file due to integer overflow. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38348
Unclassified
Aug 27, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-38343] Denial of Service via integer overflow in video scaling

Denial of Service via integer overflow in video scaling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38343
Unclassified
Aug 27, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-38345] Denial of Service via division-by-zero vulnerability in `ff_sws_init_single_context` function.

Denial of Service via division-by-zero vulnerability in `ff_sws_init_single_context` function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38345
Unclassified
Aug 27, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-38346] Denial of Service via crafted video file due to integer overflow

Denial of Service via crafted video file due to integer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38346
Unclassified
Aug 27, 2026
Medium5.0Red Hat Updated

Medium [CVE-2026-38344] Denial of Service via crafted video file

Denial of Service via crafted video file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38344
Unclassified
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59306] Spring Cloud: Potential for deserialization of untrusted types in Spring Cloud Stream.

Potential for deserialization of untrusted types in Spring Cloud Stream.

CVE-2026-59306
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59305] Spring Cloud: Partition interceptor may be improperly added while sending message.

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2

CVE-2026-59305
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59304] Spring Cloud: Improper caching of the original content type in Spring Cloud Stream Avro.

Improper caching of the original content type in Spring Cloud Stream Avro.

CVE-2026-59304
Tanzu / Spring
Aug 27, 2026