Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat

High [CVE-2026-74568] Fix race between LPI release and re-registration

Fix race between LPI release and re-registration. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74568
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74537] hold sk properly in iso_conn_ready

hold sk properly in iso_conn_ready. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74537
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74474] use pskb_network_may_pull for transmit path header pulls

use pskb_network_may_pull() for transmit path header pulls. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74474
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-74502] fix double free of out_cvts on rawmidi error

fix double free of out_cvts on rawmidi error. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74502
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74517] Cancel delayed I/O APIC EOI handling before destroying vCPUs

Cancel delayed I/O APIC EOI handling before destroying vCPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74517
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74554] fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup

fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74554
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74496] Fix use-after-free in fou_create

Fix use-after-free in fou_create(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74496
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74575] Prevent XDomain delayed work use-after-free on disconnect

Prevent XDomain delayed work use-after-free on disconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74575
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-74516] Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active

Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active. Red Hat rates this important (CVSS 7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74516
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74534] fix refcounting of iso_conn

fix refcounting of iso_conn. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74534
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-74518] fix list corruption in allocate_file_region_entries

fix list corruption in allocate_file_region_entries(). Red Hat rates this important (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74518
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-74556] Bound SCSI Response data segment to the connection buffer

Bound SCSI Response data segment to the connection buffer. Red Hat rates this important (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74556
Linux Kernel
Aug 15, 2026
Medium4.3Apache

Medium [CVE-2026-73632] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73632
Struts
Aug 15, 2026
Medium4.3Apache

Medium [CVE-2026-73631] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

CVE-2026-73631
Struts
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72428] Fix stack slot index in nospec checks

Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72428
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path

Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72245
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup

Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72403
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename

fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-72190
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72292] Initialize KVM_S390_GET_CMMA_BITS memory

Initialize KVM_S390_GET_CMMA_BITS memory. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908.

CVE-2026-72292
Unclassified
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-72454] Fix race in i3c_hci_addr_to_dev

Fix race in i3c_hci_addr_to_dev(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72454
Linux Kernel
Aug 15, 2026