Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Red Hat

High [CVE-2026-17346] pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names

pgAdmin 4: pgAdmin 4: SQL injection via unescaped object names. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.

CVE-2026-17346
Unclassified
Jul 31, 2026
High8.2Red Hat

High [CVE-2026-18141] Authentication bypass in Event-Driven Ansible via forged HTTP header

Authentication bypass in Event-Driven Ansible via forged HTTP header. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/gateway-rhel9:1785435970, ansible-automation-platform-26/gateway-rhel9:1785780020. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18141
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-18446] Host confusion vulnerability via backslash in URI authority

Host confusion vulnerability via backslash in URI authority. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-18446
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18358] gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service

gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:54512 with package gnome-remote-desktop-0:49.3-4.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-18358
Unclassified
Jul 31, 2026
High8.1Apache

High [CVE-2025-66518 +1] Apache Kyuubi Server: The security fix for CVE-2025-66518 is incomplete

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

CVE-2025-66518CVE-2026-62391
Unclassified
Jul 31, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-11770] pre-auth LDAP filter injection in CleanAllRUV status check

pre-auth LDAP filter injection in CleanAllRUV status check. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-90. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-11770
Unclassified
Jul 31, 2026
High7.5Red Hat

High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing

pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-15722
Unclassified
Jul 31, 2026
High8.5Red Hat

High [CVE-2026-10079] Deploy-time policy enforcement and visibility bypass via label injection

Deploy-time policy enforcement and visibility bypass via label injection. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.

CVE-2026-10079
Unclassified
Jul 31, 2026
High7.8NetApp

High [CVE-2026-39822] Golang Vulnerability in NetApp Products

Golang versions prior to 1.25.12, 1.26.0-0 prior to 1.26.5, and 1.27.0-0 prior to 1.27.0-rc.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-39822
Unclassified
Jul 31, 2026
High8.4NetApp

High [CVE-2026-46936 +28] July 2026 MySQL Server 8.4.0 and 9.7.0 Vulnerabilities in NetApp Products

MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 are susceptible to vulnerabilities that allow unauthenticated, high and low privileged attackers with network access via multiple protocols to compromise MySQL Server and unauthenticated and high privileged attackers with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - July 2026” for additional details. Successful attacks of these vulnerabilities can result in unauthorized read access to a subset of MySQL Server accessible data, or unauthorized update, insert or delete access to some of MySQL Server accessible data, unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) or partial denial of service (partial DOS) of MySQL Server, or a takeover of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-46936CVE-2026-47012CVE-2026-47023+26
Active IQ Unified Manager
Jul 31, 2026
High7.8Red Hat

High [CVE-2026-18157] Remote Code Execution via APT Argument Injection

Remote Code Execution via APT Argument Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88.

CVE-2026-18157
Unclassified
Jul 30, 2026
High8.9Red Hat

High [CVE-2026-66066] Remote Code Execution via Unsafe libvips Operations

Remote Code Execution via Unsafe libvips Operations. Red Hat rates this important (CVSS 8.9). Weakness: CWE-434.

CVE-2026-66066
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction

Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.

CVE-2026-12932
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-62663] Information Disclosure via Path Traversal in Media Filters

Information Disclosure via Path Traversal in Media Filters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2.

CVE-2026-62663
Unclassified
Jul 30, 2026
High7.5Apache

High [CVE-2026-28814] Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

CVE-2026-28814
Unclassified
Jul 30, 2026
High8.8Apache

High [CVE-2026-28813] Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-28813
Unclassified
Jul 30, 2026
High7.5Apache

High [CVE-2026-28811] Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-28811
Unclassified
Jul 30, 2026
High7.5Red Hat

High [CVE-2026-60075] Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing

Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:56971 with package perl-Date-Manip-0:6.85-3.el9_8.1, perl-Date-Manip-0:6.94-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-60075
Unclassified
Jul 30, 2026
High7.6VMware

High [CVE-2026-41703] Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41703
ESXiCloud FoundationWorkstation & FusionvSphere
Jul 30, 2026
High8.1Red Hat

High [CVE-2026-17544] Arbitrary code execution via out-of-bounds write in bccomp

Arbitrary code execution via out-of-bounds write in bccomp(). Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-17544
Unclassified
Jul 30, 2026