Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3251 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat Updated

Medium [CVE-2026-38345] Denial of Service via division-by-zero vulnerability in `ff_sws_init_single_context` function.

Denial of Service via division-by-zero vulnerability in `ff_sws_init_single_context` function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38345
Unclassified
Aug 27, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-38346] Denial of Service via crafted video file due to integer overflow

Denial of Service via crafted video file due to integer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38346
Unclassified
Aug 27, 2026
Medium5.0Red Hat Updated

Medium [CVE-2026-38344] Denial of Service via crafted video file

Denial of Service via crafted video file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-38344
Unclassified
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59306] Spring Cloud: Potential for deserialization of untrusted types in Spring Cloud Stream.

Potential for deserialization of untrusted types in Spring Cloud Stream.

CVE-2026-59306
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59305] Spring Cloud: Partition interceptor may be improperly added while sending message.

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2

CVE-2026-59305
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59304] Spring Cloud: Improper caching of the original content type in Spring Cloud Stream Avro.

Improper caching of the original content type in Spring Cloud Stream Avro.

CVE-2026-59304
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59303] Spring Cloud: Dynamic destination cache size is not properly bound in Spring Cloud Stream.

Dynamic destination cache size is not properly bound in Spring Cloud Stream.

CVE-2026-59303
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59302] Spring Cloud: Potential for logging sensitive data in Spring Cloud Stream.

Potential for logging sensitive data in Spring Cloud Stream.

CVE-2026-59302
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59301] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function Azure.

Potential for logging sensitive data in Spring Cloud Function Azure.

CVE-2026-59301
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59300] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function AWS.

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59300
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59299] Spring Cloud: Composition lookup can potentially poison base function in Spring Cloud Function.

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59299
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59298] Spring Cloud: Potential for improper filtering of HTTP headers in Spring Cloud Function.

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59298
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59297] Spring Cloud: Implementation of isSecure call of ServerlessHttpServletRequest does not verify the actual scheme.

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3

CVE-2026-59297
Tanzu / Spring
Aug 27, 2026
Low2.0VMware Updated

Low [CVE-2026-59291] Spring Cloud: Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

CVE-2026-59291
Tanzu / Spring
Aug 27, 2026
Low3.7VMware Updated

Low [CVE-2026-59277] Spring Security: Spring Security's InetAddressMatchers utility provides matchInternal and matchExternal builders for constructing…

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network.

CVE-2026-59277
Tanzu / Spring
Aug 27, 2026
UnratedVMware Updated

Advisory [CVE-2026-59314] Spring Framework: Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response sp…

Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8

CVE-2026-59314
Tanzu / Spring
Aug 27, 2026
Critical9.6Ubiquiti

Critical [CVE-2026-77532] malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.

CVE-2026-77532
EdgeRouter / EdgeSwitch
Aug 26, 2026
Critical9.8Ubiquiti

Critical [CVE-2026-77557] malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.

CVE-2026-77557
UniFi Protect
Aug 26, 2026
Critical10.0Ubiquiti

Critical [CVE-2026-77554] malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.

CVE-2026-77554
UniFi Access / Talk / Connect
Aug 26, 2026
Critical9.9Ubiquiti

Critical [CVE-2026-77553] malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

CVE-2026-77553
UniFi Access / Talk / Connect
Aug 26, 2026