Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-17543] SQL injection via improper backslash escaping
SQL injection via improper backslash escaping. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-18353] Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass
Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.
High [CVE-2026-47882] Spring Boot: When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud F…
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
High [CVE-2026-47858] Spring Boot: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applic…
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
High [CVE-2026-58043] Unauthorized filesystem access due to Permission Model enforcement flaw
Unauthorized filesystem access due to Permission Model enforcement flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-16529] Denial of Service due to signed integer overflow
Denial of Service due to signed integer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16527] PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules
PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16526] Privilege escalation to root via linux_sockets PMDA vulnerability
Privilege escalation to root via linux_sockets PMDA vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-403. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16524] PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection
PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-17986] Insufficient policy enforcement in Bluetooth
Insufficient policy enforcement in Bluetooth. Red Hat rates this low (CVSS 8.7). Weakness: CWE-346.
High [CVE-2026-17985] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 8.2). Weakness: CWE-653.
High [CVE-2026-17918] Use after free in Sync
Use after free in Sync. Red Hat rates this low (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-17896] Use after free in DevTools
Use after free in DevTools. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-825.
High [CVE-2026-17888] Insufficient validation of untrusted input in WebUI
Insufficient validation of untrusted input in WebUI. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1286.
High [CVE-2026-17884] Object lifecycle issue in WebRTC
Object lifecycle issue in WebRTC. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-1341.
High [CVE-2026-17887] Use after free in TabStrip
Use after free in TabStrip. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-17886] Use after free in Enterprise
Use after free in Enterprise. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-17881] Use after free in WebXR
Use after free in WebXR. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-17878] Inappropriate implementation in CSS
Inappropriate implementation in CSS. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-79.
High [CVE-2026-17877] Inappropriate implementation in Chromoting
Inappropriate implementation in Chromoting. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-358.