Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

7788 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.4Splunk

Medium [CVE-2026-76255] Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another user into running arbitrary Search Processing Language (SPL) commands through the Data Model Editor using the permissions of the affected user. The commands could access all relevant data available to the affected user and affect system integrity. The vulnerability is possible because Splunk Web does not apply SPL safeguards for risky commands when the Data Model Editor runs the base search for auto-extracted fields. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who does not hold the "admin" or "power" Splunk roles should not be able to exploit the vulnerability at will. For more information see SPL safeguards for risky commands ( ) and Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.

CVE-2026-76255
Splunk Enterprise
Aug 19, 2026
Medium6.8Splunk

Medium [CVE-2026-76252] Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run unauthorized JavaScript in that user's browser. This could allow for unauthorized access to all relevant data available to that user and actions that affect system integrity. The Cross-Site Scripting (XSS) is possible because Splunk Web does not validate the origin and source of messages received by a page message handler. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.

CVE-2026-76252
Splunk Enterprise
Aug 19, 2026
Medium6.8Red Hat

Medium [CVE-2026-76827] UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)

UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering). Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-indexer-rhel9:1787688957, rhacm2/acm-search-indexer-rhel9:1787247085, rhacm2/acm-search-indexer-rhel9:1787250074, rhacm2/acm-search-indexer-rhel9:1787262474. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-76827
Unclassified
Aug 19, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-68554] Unauthorized actions or resource manipulation via STUN request modification

Unauthorized actions or resource manipulation via STUN request modification. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-354.

CVE-2026-68554
Unclassified
Aug 19, 2026
Medium5.3pfSense

Medium [CVE-2026-67189] pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.

CVE-2026-67189
pfSense PluspfSense CE
Aug 19, 2026
Medium5.4Red Hat

Medium [CVE-2026-69159] Out-of-bounds read leads to denial of service and information disclosure

Out-of-bounds read leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-69159
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63652] Denial of Service and heap corruption via malformed RDP audio PDU

Denial of Service and heap corruption via malformed RDP audio PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-63652
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation

Denial of Service via ADPCM frame size calculation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-63117
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.2Red Hat

Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription

annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-volsync-addon-controller-rhel9:1787266360, rhacm2/acm-volsync-addon-controller-rhel9:1787683560, rhacm2/acm-volsync-addon-controller-rhel9:1787266556, rhacm2/acm-volsync-addon-controller-rhel9:1787266564. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-18874
Unclassified
Aug 19, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-55648] Integer overflow allows out-of-bounds read via malicious RDP server

Integer overflow allows out-of-bounds read via malicious RDP server. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55648
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-55564] Out-of-bounds read in glyph cache leads to denial of service and information disclosure

Out-of-bounds read in glyph cache leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55564
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.8Red Hat Updated

Medium [CVE-2026-75145] Out-of-bounds memory access due to integer narrowing conversion

Out-of-bounds memory access due to integer narrowing conversion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75145
Unclassified
Aug 19, 2026
Medium5.4Cisco

Medium [CVE-2026-20232] Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: Industrial Ethernet Switches.

CVE-2026-20232
Switches
Aug 19, 2026
Medium5.0Cisco

Medium [CVE-2026-20314] Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20314
Unified Communications
Aug 19, 2026
Medium6.5Cisco

Medium [CVE-2026-20327] Cisco Unified Intelligence Center SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20327
Unclassified
Aug 19, 2026
Medium5.3Cisco

Medium [CVE-2026-20177] Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible. This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: Industrial Ethernet Switches.

CVE-2026-20177
Switches
Aug 19, 2026
Medium6.1Cisco

Medium [CVE-2026-20302] Cisco RoomOS Stack Overflow Vulnerability

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: RoomOS Software.

CVE-2026-20302
Unclassified
Aug 19, 2026
Medium6.3Red Hat

Medium [CVE-2026-76878] aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization

aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-76878
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76231] Arbitrary command execution via unsanitized dependency names

Arbitrary command execution via unsanitized dependency names. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.

CVE-2026-76231
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76228] Arbitrary Code Execution via malicious Gradle Wrapper properties

Arbitrary Code Execution via malicious Gradle Wrapper properties. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.

CVE-2026-76228
Unclassified
Aug 19, 2026