Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-17661] Use after free in Loader
Use after free in Loader. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-17657] Use after free in Navigation
Use after free in Navigation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-17654] Race in Updater
Race in Updater. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-367.
High [CVE-2026-18378] cluster pull-secret token exfiltration via user-controlled api_url (SSRF / confused deputy)
cluster pull-secret token exfiltration via user-controlled api_url (SSRF / confused deputy). Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.
High [CVE-2026-18381] operator service-account token exfiltration via user-controlled Prometheus service_address
operator service-account token exfiltration via user-controlled Prometheus service_address. Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.
High [CVE-2026-60005] NGINX Vulnerability in NetApp Products
NGINX versions 1.15.8 prior to 1.30.4 and 1.31 prior to 1.31.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: NetApp Console Agent Container (static-file-server). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-13321] ISC BIND Vulnerability in NetApp Products
ISC BIND versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-11605] ISC BIND Vulnerability in NetApp Products
ISC BIND versions 9.20.0 through 9.20.24 and 9.21.0 through 9.21.23 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-12617] ISC BIND Vulnerability in NetApp Products
ISC BIND versions 9.18.0 through 9.18.50 and 9.20.0 through 9.20.24 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-5056] Arbitrary code execution via stack-based buffer overflow in qtdemux
Arbitrary code execution via stack-based buffer overflow in qtdemux. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:49508 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-6267] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
High [CVE-2026-12436] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.
High [CVE-2026-15975] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.
High [CVE-2026-18022] Arbitrary Code Execution via Integer Wraparound
Arbitrary Code Execution via Integer Wraparound. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-67201] Server-Side Request Forgery (SSRF) bypass due to URL parser differential
Server-Side Request Forgery (SSRF) bypass due to URL parser differential. Red Hat rates this important (CVSS 8.6). Weakness: CWE-168.
High [CVE-2026-18255] Global read-only superuser can view robot account tokens
Global read-only superuser can view robot account tokens. Red Hat rates this important (CVSS 7.2). Weakness: CWE-863.
High [CVE-2026-13697] Information disclosure and Denial of Service via malformed Cache-Control directives
Information disclosure and Denial of Service via malformed Cache-Control directives. Red Hat rates this important (CVSS 7.4). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-20028 +21] Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 Critical 9.9 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities High 8.8 Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability 8.6 7.7 Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability Medium 6.5 Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability 6.3 Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability 5.7 Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability 5.0 Cisco Integrated Management Controller Cross-Site Scripting Vulnerability 4.8
High [CVE-2026-55707] Shared-network consumer can re-scope another project's subnets via subnetpool onboarding
Shared-network consumer can re-scope another project's subnets via subnetpool onboarding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863.
High [CVE-2026-55995] Denial of Service via double-free in iSNS attribute decoder
Denial of Service via double-free in iSNS attribute decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Red Hat lists fixing advisory RHSA-2026:53848 with package isns-utils-0:0.103-1.el10_2.1, isns-utils-0:0.99-1.el8_10.1, isns-utils-0:0.101-4.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.