Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3305 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat

High [CVE-2026-67305] Remote Code Execution via Heap Buffer Overflow in Clipboard Processing

Remote Code Execution via Heap Buffer Overflow in Clipboard Processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122.

CVE-2026-67305
Unclassified
Aug 1, 2026
High7.5Red Hat

High [CVE-2026-18536] Predictable random numbers due to unencrypted remote entropy sources

Predictable random numbers due to unencrypted remote entropy sources. Red Hat rates this important (CVSS 7.5). Weakness: CWE-319.

CVE-2026-18536
Unclassified
Aug 1, 2026
High7.1Red Hat

High [CVE-2026-65981] Authorization bypass allows session takeover via MOBILITY-TICKET session resume

Authorization bypass allows session takeover via MOBILITY-TICKET session resume. Red Hat rates this important (CVSS 7.1). Weakness: CWE-303.

CVE-2026-65981
Unclassified
Jul 31, 2026
High7.4Red Hat

High [CVE-2026-68770] Remote Code Execution via Security Control Bypass

Remote Code Execution via Security Control Bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-454. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-68770
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-62959] Pre-authentication heap memory disclosure

Pre-authentication heap memory disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-908.

CVE-2026-62959
Unclassified
Jul 31, 2026
High8.8Red Hat

High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names

pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.

CVE-2026-17346
Unclassified
Jul 31, 2026
High8.2Red Hat

High [CVE-2026-18141] Authentication bypass in Event-Driven Ansible via forged HTTP header

Authentication bypass in Event-Driven Ansible via forged HTTP header. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/gateway-rhel9:1785435970, ansible-automation-platform-26/gateway-rhel9:1785780020. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18141
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-18446] Host confusion vulnerability via backslash in URI authority

Host confusion vulnerability via backslash in URI authority. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-18446
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18358] gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service

gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:54512 with package gnome-remote-desktop-0:49.3-4.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-18358
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-11770] pre-auth LDAP filter injection in CleanAllRUV status check

pre-auth LDAP filter injection in CleanAllRUV status check. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-90. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-11770
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing

pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-15722
Unclassified
Jul 31, 2026
High8.5Red Hat

High [CVE-2026-10079] Deploy-time policy enforcement and visibility bypass via label injection

Deploy-time policy enforcement and visibility bypass via label injection. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.

CVE-2026-10079
Unclassified
Jul 31, 2026
High7.8Red Hat

High [CVE-2026-18157] Remote Code Execution via APT Argument Injection

Remote Code Execution via APT Argument Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88.

CVE-2026-18157
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-18140] Denial of Service via uncontrolled recursion with deeply nested JSON

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild. This can make the affected server unavailable to legitimate users. Red Hat products utilizing `smithy-rs` generated servers, such as components in Red Hat Enterprise Linux and Red Hat Trusted Artifact Signer, are susceptible to service disruption if exposed to untrusted networks. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected Red Hat products: Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Trusted Artifact Signer; Red Hat Trusted Profile Analyzer. Red Hat lists Confidential Compute Attestation; Red Hat Trusted Profile Analyzer as not affected. Will not fix / out of support: Red Hat Trusted Profile Analyzer. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: goose.

CVE-2026-18140
Red Hat Enterprise Linux
Jul 30, 2026
High8.9Red Hat

High [CVE-2026-66066] Remote Code Execution via Unsafe libvips Operations

Remote Code Execution via Unsafe libvips Operations. Red Hat rates this important (CVSS 8.9). Weakness: CWE-434.

CVE-2026-66066
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-61536] Arbitrary code execution via unsafe tool definition import

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable Python attribute (e.g. os.system, subprocess.getoutput) can be selected. When the LLM emits a tool_calls entry whose function.name matches the attacker-supplied tool name, the resolved callable is invoked with kwargs decoded from tool_call.function.arguments, yielding arbitrary code execution in the banks-hosting process. This is distinct from GHSA-gphh-9q3h-jgpp / CVE-2026-44209. That advisory was fixed in 2.4.2 by switching src/banks/env.py from Environment to SandboxedEnvironment. The fix does not touch src/banks/extensions/completion.py, and the unsafe import + getattr chain still executes on 2.4.2. The malicious Tool JSON is plain text in the rendered template body — it requires no Jinja attribute access, so the sandbox is irrelevant. This issue has been fixed in version 2.4.3. A flaw was found in Banks, a tool for generating LLM prompts. This vulnerability allows a remote attacker to achieve arbitrary code execution by injecting a malicious tool definition into a template.

CVE-2026-61536
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction

Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.

CVE-2026-12932
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-62663] Information Disclosure via Path Traversal in Media Filters

Information Disclosure via Path Traversal in Media Filters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2.

CVE-2026-62663
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-60075] Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing

Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:56971 with package perl-Date-Manip-0:6.85-3.el9_8.1, perl-Date-Manip-0:6.94-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-60075
Unclassified
Jul 30, 2026
High8.1Red Hat

High [CVE-2026-17544] Arbitrary code execution via out-of-bounds write in bccomp

Arbitrary code execution via out-of-bounds write in bccomp(). Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-17544
Unclassified
Jul 30, 2026