Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3332 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Red Hat

High [CVE-2026-64483] bound the sample count to the packet payload

bound the sample count to the packet payload. Red Hat rates this important (CVSS 7). Weakness: CWE-120.

CVE-2026-64483
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64438] qat - fix VF2PF work teardown race in adf_disable_sriov

qat - fix VF2PF work teardown race in adf_disable_sriov(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64438
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64371] protect ptrace_may_access with exec_update_lock (part 1)

protect ptrace_may_access() with exec_update_lock (part 1). Red Hat rates this moderate (CVSS 7).

CVE-2026-64371
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64386] fix query_info replay double-free

fix query_info() replay double-free. Red Hat rates this important (CVSS 7). Weakness: CWE-1341.

CVE-2026-64386
Unclassified
Jul 25, 2026
High8.8Red Hat

High [CVE-2026-66041] Arbitrary code execution via crafted PGS/SUP subtitle file

Arbitrary code execution via crafted PGS/SUP subtitle file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66041
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66040] Arbitrary code execution via crafted PNG image

Arbitrary code execution via crafted PNG image. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66040
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66039] Arbitrary code execution via crafted CAF file

Arbitrary code execution via crafted CAF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66039
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66036] Arbitrary code execution via crafted video in vf_hqdn3d filter

Arbitrary code execution via crafted video in vf_hqdn3d filter. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66036
Unclassified
Jul 24, 2026
High8.5Red Hat

High [CVE-2026-17107] Impersonation header injection in service-proxy grants cluster-admin on every managed cluster

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster. This is due to improper handling of impersonation group headers, enabling unauthorized administrative access. While the impact of successful exploitation is severe, the attack requires authenticated access to the ACM hub cluster, which is a management-plane component not typically exposed to untrusted networks. Exploitation also depends on knowledge of the cluster-proxy architecture and deliberate construction of requests targeting specific managed clusters. These prerequisites significantly reduce the likelihood of opportunistic or widespread exploitation. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-441. Red Hat fixing advisory: RHSA-2026:46885, RHSA-2026:47388, RHSA-2026:47974, RHSA-2026:48284, RHSA-2026:47949, RHSA-2026:47735, RHSA-2026:47953.

CVE-2026-17107
Unclassified
Jul 24, 2026
High8.4Red Hat

High [CVE-2026-66140] Privilege escalation via directory traversal due to mishandled queue-name arguments

Privilege escalation via directory traversal due to mishandled queue-name arguments. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22.

CVE-2026-66140
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66138] Arbitrary code execution via malicious configuration

Arbitrary code execution via malicious configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.

CVE-2026-66138
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64255] validate sta_mask before ffs in BA session handlers

validate sta_mask before ffs() in BA session handlers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823.

CVE-2026-64255
Unclassified
Jul 24, 2026
HighRed Hat

High [CVE-2026-64218] fix report_work leak on backbone_gw purge

fix report_work leak on backbone_gw purge. Red Hat rates this important. Weakness: CWE-825.

CVE-2026-64218
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64226] Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn

Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-64226
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64219] Validate payload length and link_index in dc_process_dmub_aux_transfer_async

Validate payload length and link_index in dc_process_dmub_aux_transfer_async. Red Hat rates this important (CVSS 7). Weakness: CWE-120.

CVE-2026-64219
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64247] Denial of Service due to out-of-bounds read

Denial of Service due to out-of-bounds read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64247
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64217] Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation

Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64217
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64251] Linux kernel: Use-after-free in pwrseq_debugfs_seq_next can lead to denial of service

Linux kernel: Use-after-free in pwrseq_debugfs_seq_next() can lead to denial of service. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.

CVE-2026-64251
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64221] Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service

Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-64221
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64208] crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.

CVE-2026-64208
Unclassified
Jul 24, 2026