Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

240 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7Red Hat

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.

CVE-2026-67294
Unclassified
Aug 1, 2026
Low3.1Red Hat

Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys

Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.

CVE-2026-54787
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens

OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.

CVE-2026-18569
Unclassified
Jul 31, 2026
Low3.4Red Hat

Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check

OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.

CVE-2026-18209
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass

Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.

CVE-2026-18206
Unclassified
Jul 31, 2026
Low3.4Vendor: MediumRed Hat

Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution

SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.

CVE-2026-18217
Unclassified
Jul 31, 2026
Low2.7VMware

Low [CVE-2026-41709] ESX insufficient logging vulnerability

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41709
ESXiCloud FoundationvSphere
Jul 30, 2026
Low3.3VMware

Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59326
Tanzu / Spring
Jul 30, 2026
Low3.3Red Hat

Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions

Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56847
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18018] Inappropriate implementation in Updater

Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).

CVE-2026-18018
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools

Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.

CVE-2026-18014
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18010] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.

CVE-2026-18010
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18007] Inappropriate implementation in Input

Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.

CVE-2026-18007
Unclassified
Jul 30, 2026
Low3.2Red Hat

Low [CVE-2026-18004] Insufficient policy enforcement in Speech

Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.

CVE-2026-18004
Unclassified
Jul 30, 2026
Low3.1Red Hat

Low [CVE-2026-18001] Inappropriate implementation in WebGL

Inappropriate implementation in WebGL. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825.

CVE-2026-18001
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18000] Insufficient policy enforcement in USB

Insufficient policy enforcement in USB. Red Hat rates this low (CVSS 2.8). Weakness: CWE-346.

CVE-2026-18000
Unclassified
Jul 30, 2026
Low2.4Red Hat

Low [CVE-2026-17997] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low (CVSS 2.4). Weakness: CWE-368.

CVE-2026-17997
Unclassified
Jul 30, 2026
Low3.9Red Hat

Low [CVE-2026-17996] Inappropriate implementation in Browser

Inappropriate implementation in Browser. Red Hat rates this low (CVSS 3.9). Weakness: CWE-807.

CVE-2026-17996
Unclassified
Jul 30, 2026
Low3.9Red Hat

Low [CVE-2026-17993] Race in Updater

Race in Updater. Red Hat rates this low (CVSS 3.9). Weakness: CWE-367.

CVE-2026-17993
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-17992] Uninitialized Use in Skia

Uninitialized Use in Skia. Red Hat rates this low. Weakness: CWE-824.

CVE-2026-17992
Unclassified
Jul 30, 2026