Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Red Hat

Medium [CVE-2026-18727] Integer underflow in iscsiuio DHCPv6 parsing

Integer underflow in iscsiuio DHCPv6 parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-18727
Unclassified
Aug 12, 2026
Medium6.5Red Hat

Medium [CVE-2026-18726] Denial of service in iscsiuio Router Advertisement parsing

Denial of service in iscsiuio Router Advertisement parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-18726
Unclassified
Aug 12, 2026
Medium4.7Red Hat

Medium [CVE-2026-73490] SVG `href` attribute bypasses local-reference restriction

SVG `href` attribute bypasses local-reference restriction. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-184.

CVE-2026-73490
Unclassified
Aug 12, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-73427] Cross-site scripting via crafted JSON drag-and-drop

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18. A remote attacker could exploit this vulnerability by convincing a victim to drag and drop a specially crafted JSON payload into an editor using the Level0InputController. This could bypass sanitization and allow the injection of executable JavaScript into the web page, leading to cross-site scripting (XSS). The version of action_text-trix shipped in Red Hat products is not affected by this vulnerability as it already includes the fix. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-79.

CVE-2026-73427
Unclassified
Aug 12, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-73423] Cross-site Request Forgery (CSRF) due to origin check bypass in `astro/hono` pipeline

Cross-site Request Forgery (CSRF) due to origin check bypass in `astro/hono` pipeline. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-940. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-73423
Unclassified
Aug 12, 2026
Medium6.6Red Hat

Medium [CVE-2026-73433] unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write

unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:55436 with package gstreamer1-plugins-good-0:1.16.1-7.el8_10.3, gstreamer1-plugins-good-0:1.26.7-2.el10_2.5, gstreamer1-plugins-good-0:1.22.12-7.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-73433
Unclassified
Aug 12, 2026
Medium6.1Red Hat

Medium [CVE-2026-73434] out-of-bounds read in avidemux vprp video field descriptor parsing

out-of-bounds read in avidemux vprp video field descriptor parsing. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55436 with package gstreamer1-plugins-good-0:1.16.1-7.el8_10.3, gstreamer1-plugins-good-0:1.26.7-2.el10_2.5, gstreamer1-plugins-good-0:1.22.12-7.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-73434
Unclassified
Aug 12, 2026
Medium4.3GitLab

Medium [CVE-2026-4879] GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint

GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.

CVE-2026-4879
Unclassified
Aug 12, 2026
Medium4.3GitLab

Medium [CVE-2026-6821] GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint

GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.

CVE-2026-6821
Unclassified
Aug 12, 2026
Medium4.3GitLab

Medium [CVE-2026-18433] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.

CVE-2026-18433
Unclassified
Aug 12, 2026
Medium5.3GitLab

Medium [CVE-2026-7427] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.

CVE-2026-7427
Unclassified
Aug 12, 2026
Medium4.3GitLab

Medium [CVE-2026-8667] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.

CVE-2026-8667
Unclassified
Aug 12, 2026
Medium4.3GitLab

Medium [CVE-2026-18244] GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page

GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page.

CVE-2026-18244
Unclassified
Aug 12, 2026
Medium5.8Vendor: HighRed Hat

Medium [CVE-2026-19130] cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization

cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization. Red Hat rates this important (CVSS 5.8). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/provider-credential-controller-rhel9:1787259099, multicluster-engine/provider-credential-controller-rhel9:1787176886, multicluster-engine/provider-credential-controller-rhel9:1787239595, multicluster-engine/provider-credential-controller-rhel9:1787176716. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-19130
Unclassified
Aug 12, 2026
Medium6.1Apache

Medium [CVE-2026-73237] XSS vulnerability in Markdown handling in Apache Allura

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-73237
Unclassified
Aug 12, 2026
Medium6.1Apache

Medium [CVE-2026-73238] XSS vulnerability in code display in Apache Allura

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-73238
Unclassified
Aug 12, 2026
Medium6.5Apache

Medium [CVE-2026-73239] Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-73239
Unclassified
Aug 12, 2026
Medium5.4Red Hat

Medium [CVE-2026-73295] Material for MkDocs: DOM-based Cross-Site Scripting via crafted URL parameter

Material for MkDocs: DOM-based Cross-Site Scripting via crafted URL parameter. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Developer Hub; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Self-service automation portal 2.

CVE-2026-73295
Unclassified
Aug 12, 2026
Medium6.1Vendor: LowPalo Alto

Medium [CVE-2026-0292] Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

CVE-2026-0292
Prisma Access
Aug 12, 2026
Medium4.8Vendor: LowPalo Alto

Medium [CVE-2026-0291] Prisma Access Agent: Authenticated Limited File Deletion on Linux

CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux

CVE-2026-0291
Prisma Access
Aug 12, 2026