Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1Apache

Critical [CVE-2026-65583] Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.

CVE-2026-65583
Unclassified
Aug 6, 2026
Critical9.8Apache

Critical [CVE-2026-68079] In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVE-2026-68079
Unclassified
Aug 6, 2026
Critical9.8Apache

Critical [CVE-2026-66909] Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVE-2026-66909
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-70632] Arbitrary Code Execution in CFHD Decoder via Crafted AVI File

Arbitrary Code Execution in CFHD Decoder via Crafted AVI File. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-70632
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-70628] Arbitrary code execution via crafted WTV file in DVB subtitle parser

Arbitrary code execution via crafted WTV file in DVB subtitle parser. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-70628
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-71430] Denial of Service due to excessive string length in replacements

Denial of Service due to excessive string length in replacements. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.

CVE-2026-71430
Unclassified
Aug 6, 2026
High8.0Red Hat

High [CVE-2026-19177] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8). Weakness: CWE-1289.

CVE-2026-19177
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19175] Remote sandbox escape via use-after-free in Payments

Remote sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19175
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19174] Arbitrary code execution via crafted HTML page

Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.

CVE-2026-19174
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19171] Sandbox escape via use-after-free in Media component

Sandbox escape via use-after-free in Media component. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.

CVE-2026-19171
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19166] Sandbox escape due to use-after-free in Web Authentication

Sandbox escape due to use-after-free in Web Authentication. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.

CVE-2026-19166
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19164] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1286.

CVE-2026-19164
Unclassified
Aug 6, 2026
High8.0Red Hat

High [CVE-2026-19163] Sandbox escape via use-after-free in Media component

Sandbox escape via use-after-free in Media component. Red Hat rates this important (CVSS 8). Weakness: CWE-825.

CVE-2026-19163
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19162] Arbitrary code execution via out-of-bounds write in V8.

Arbitrary code execution via out-of-bounds write in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-19162
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19158] Arbitrary code execution via use-after-free in Views

Arbitrary code execution via use-after-free in Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19158
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-19159] Arbitrary code execution via use-after-free in Views

Arbitrary code execution via use-after-free in Views. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-19159
Unclassified
Aug 6, 2026
High8.7Red Hat

High [CVE-2026-19153] Site isolation bypass via insufficient input validation in Workers

Site isolation bypass via insufficient input validation in Workers. Red Hat rates this important (CVSS 8.7). Weakness: CWE-807.

CVE-2026-19153
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-19156] Heap buffer overflow allows heap corruption via malicious extension

Heap buffer overflow allows heap corruption via malicious extension. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.

CVE-2026-19156
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19151] Arbitrary code execution via use-after-free in V8

Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19151
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19152] Sandbox escape via insufficient policy enforcement in Navigation

Sandbox escape via insufficient policy enforcement in Navigation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-266.

CVE-2026-19152
Unclassified
Aug 6, 2026