Complete feed
Security advisories & CVEs
1779 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-18726] Denial of service in iscsiuio Router Advertisement parsing
Denial of service in iscsiuio Router Advertisement parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-73490] SVG `href` attribute bypasses local-reference restriction
SVG `href` attribute bypasses local-reference restriction. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-184.
Medium [CVE-2026-73427] Cross-site scripting via crafted JSON drag-and-drop
Cross-site scripting via crafted JSON drag-and-drop. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-79.
Medium [CVE-2026-73423] Cross-site Request Forgery (CSRF) due to origin check bypass in `astro/hono` pipeline
Cross-site Request Forgery (CSRF) due to origin check bypass in `astro/hono` pipeline. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-940. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-73433] unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write
unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:55436 with package gstreamer1-plugins-good-0:1.16.1-7.el8_10.3, gstreamer1-plugins-good-0:1.26.7-2.el10_2.5, gstreamer1-plugins-good-0:1.22.12-7.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-73434] out-of-bounds read in avidemux vprp video field descriptor parsing
out-of-bounds read in avidemux vprp video field descriptor parsing. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55436 with package gstreamer1-plugins-good-0:1.16.1-7.el8_10.3, gstreamer1-plugins-good-0:1.26.7-2.el10_2.5, gstreamer1-plugins-good-0:1.22.12-7.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-4879] GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint
GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.
Medium [CVE-2026-6821] GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint
GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.
Medium [CVE-2026-18433] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.
Medium [CVE-2026-7427] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.
Medium [CVE-2026-8667] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.
Medium [CVE-2026-18244] GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page
GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page.
Medium [CVE-2026-19130] cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization
cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization. Red Hat rates this important (CVSS 5.8). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/provider-credential-controller-rhel9:1787259099, multicluster-engine/provider-credential-controller-rhel9:1787176886, multicluster-engine/provider-credential-controller-rhel9:1787239595, multicluster-engine/provider-credential-controller-rhel9:1787176716. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Medium [CVE-2026-73237] XSS vulnerability in Markdown handling in Apache Allura
XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Medium [CVE-2026-73238] XSS vulnerability in code display in Apache Allura
XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Medium [CVE-2026-73239] Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Medium [CVE-2026-73295] Material for MkDocs: DOM-based Cross-Site Scripting via crafted URL parameter
Material for MkDocs: DOM-based Cross-Site Scripting via crafted URL parameter. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Developer Hub; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Self-service automation portal 2.
Medium [CVE-2026-0292] Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
Medium [CVE-2026-0291] Prisma Access Agent: Authenticated Limited File Deletion on Linux
CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux
Medium [CVE-2026-0301] PAN-OS: Information Disclosure Vulnerability in URL Filtering
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering Affected products named by the advisory: Cloud NGFW; Prisma Access.