Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Red Hat

High [CVE-2026-74556] Bound SCSI Response data segment to the connection buffer

Bound SCSI Response data segment to the connection buffer. Red Hat rates this important (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74556
Linux Kernel
Aug 15, 2026
Medium4.3Apache

Medium [CVE-2026-73632] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73632
Struts
Aug 15, 2026
Medium4.3Apache

Medium [CVE-2026-73631] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73631
Struts
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72428] Fix stack slot index in nospec checks

Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72428
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path

Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72245
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup

Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72403
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename

fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-72190
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72292] Initialize KVM_S390_GET_CMMA_BITS memory

Initialize KVM_S390_GET_CMMA_BITS memory. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908.

CVE-2026-72292
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72454] Fix race in i3c_hci_addr_to_dev

Fix race in i3c_hci_addr_to_dev(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72454
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72025] Reject buffer reuse with different data length

Reject buffer reuse with different data length. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72025
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72396] Prevent reading uninitialized stack

Prevent reading uninitialized stack. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-72396
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72305] avoid leaking information to userspace

avoid leaking information to userspace. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72305
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72309] Fix leak in trace_remote_alloc_buffer error path

Fix leak in trace_remote_alloc_buffer() error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.

CVE-2026-72309
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72470] resize log->one_page_buf when adopting on-disk page size

resize log->one_page_buf when adopting on-disk page size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-131.

CVE-2026-72470
Unclassified
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72011] Add missing array_index_nospec call to memtop_get_page_count

Add missing array_index_nospec() call to memtop_get_page_count(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72011
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72490] fix stainfo check in rtw_aes_decrypt

fix stainfo check in rtw_aes_decrypt. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-72490
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72189] fail attrlist updates when the superblock is inactive

fail attrlist updates when the superblock is inactive. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-72189
Unclassified
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72068] Use u64 multiplication in update_rlimit_cpu

Use u64 multiplication in update_rlimit_cpu(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72068
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72296] require ETH_HLEN to be pullable in ife_decode

require ETH_HLEN to be pullable in ife_decode(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-72296
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72458] fix NULL pointer dereference in unpack_pdb

fix NULL pointer dereference in unpack_pdb. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-72458
Unclassified
Aug 15, 2026