Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat Updated

Medium [CVE-2026-74576] prevent unbounded recursion in free path with new kmalloc type

prevent unbounded recursion in free path with new kmalloc type. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74576
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74524] Fix out-of-bounds page-table walk during memory hot-remove

Fix out-of-bounds page-table walk during memory hot-remove. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-74524
Unclassified
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74523] sync udp_tunnel ports outside qede_lock in the recovery path

sync udp_tunnel ports outside qede_lock in the recovery path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74523
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74463] Cache host clock rate at probe to prevent CCF prepare_lock deadlock

Cache host clock rate at probe to prevent CCF prepare_lock deadlock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-74463
Unclassified
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74466] Close speculative mem read possibility

Close speculative mem read possibility. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74466
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74540] fix UAF in l2cap_le_connect_rsp

fix UAF in l2cap_le_connect_rsp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74540
Linux Kernel
Aug 15, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-49263] Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation

Denial of Service and parser desynchronization via WebAssembly `br_table` instruction-size truncation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49263
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-49282] Denial of service via out-of-bounds read in M68K and RISCV backends

Denial of service via out-of-bounds read in M68K and RISCV backends. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-49282
Red Hat Enterprise Linux
Aug 14, 2026
Medium6.7Red Hat Updated

Medium [CVE-2026-46380] Server-Side Request Forgery via unvalidated URL in remote fetching subsystem

Server-Side Request Forgery via unvalidated URL in remote fetching subsystem. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-918. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46380
Unclassified
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-73051] HTTP Request Smuggling via malformed HTTP/1.1 headers

HTTP Request Smuggling via malformed HTTP/1.1 headers. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Update Service; Red Hat package: keylime-agent-rust; and 1 more. Affected products named by the advisory: Red Hat package: trustee.

CVE-2026-73051
Red Hat Enterprise Linux
Aug 14, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-72814] Information Disclosure via relative path traversal

Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.

CVE-2026-72814
Unclassified
Aug 14, 2026
Medium5.3NetApp

Medium [CVE-2026-45205] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux and Unix are susceptible to a vulnerability in commons-configuration2-2.10.1. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-45205
Unclassified
Aug 14, 2026
Medium5.5NetApp

Medium [CVE-2026-18097] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-18097
Unclassified
Aug 14, 2026
Medium4.3NetApp

Medium [CVE-2026-16480] IBM Db2 Vulnerability in NetApp Products

IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow a non-privileged user to bypass authority checks and modify database catalog data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-16480
Unclassified
Aug 14, 2026
Medium5.5NetApp

Medium [CVE-2026-58084] FreeBSD Vulnerability in NetApp Products

FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user who can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2) disclose sensitive kernel data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-58084
Unclassified
Aug 14, 2026
Medium5.4Red Hat

Medium [CVE-2026-73621] Arbitrary File Truncation via Commit.count Argument Injection

Arbitrary File Truncation via Commit.count() Argument Injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73621
Unclassified
Aug 13, 2026
Medium6.5Red Hat

Medium [CVE-2026-73619] Arbitrary file read vulnerability via `Repo.archive `

Arbitrary file read vulnerability via `Repo.archive()`. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.

CVE-2026-73619
Unclassified
Aug 13, 2026
Medium5.5Red Hat

Medium [CVE-2026-68454] Fix handling of AIF enable without AISB

Fix handling of AIF enable without AISB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68454
Linux Kernel
Aug 13, 2026
Medium5.7Docker

Medium [CVE-2026-18171] Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.

CVE-2026-18171
Docker Desktop
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68429] Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe

Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-68429
Linux Kernel
Aug 12, 2026