Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5NetApp

Medium [CVE-2026-63136] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.0.0 through 8.19.14, 9.0.0 through 9.2.8, and 9.3.0 through 9.3.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63136
Unclassified
Aug 7, 2026
Medium5.1Red Hat

Medium [CVE-2026-71498] Information disclosure via out-of-bounds read with malformed UTF-8 input

Information disclosure via out-of-bounds read with malformed UTF-8 input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-125.

CVE-2026-71498
Unclassified
Aug 6, 2026
Medium6.8Red Hat

Medium [CVE-2026-19167] Cross-origin data leakage via integer overflow in GPU

Cross-origin data leakage via integer overflow in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190.

CVE-2026-19167
Unclassified
Aug 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-19146] Google Chrome (Android): Information disclosure via uninitialized GPU memory use

Google Chrome (Android): Information disclosure via uninitialized GPU memory use. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824.

CVE-2026-19146
Unclassified
Aug 6, 2026
Medium6.7Red Hat

Medium [CVE-2026-19139] OS-level privilege escalation due to a race condition via a malicious file

OS-level privilege escalation due to a race condition via a malicious file. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367.

CVE-2026-19139
Unclassified
Aug 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-71439] Denial of Service via Radar Diagrams 'ticks' parameter

Denial of Service via Radar Diagrams 'ticks' parameter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1050.

CVE-2026-71439
Unclassified
Aug 6, 2026
Medium4.3Red Hat

Medium [CVE-2026-50159] CSS injection allows altering page elements via diagram input

CSS injection allows altering page elements via diagram input. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-79.

CVE-2026-50159
Unclassified
Aug 6, 2026
Medium6.7Red Hat

Medium [CVE-2026-64654] Terminal escape sequence injection allows command execution

Terminal escape sequence injection allows command execution. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.

CVE-2026-64654
Unclassified
Aug 6, 2026
Medium5.4Red Hat

Medium [CVE-2026-64653] Path traversal via unescaped URL variables

Path traversal via unescaped URL variables. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-22.

CVE-2026-64653
Unclassified
Aug 6, 2026
Medium5.3Apache

Medium [CVE-2026-64640] Apache Polaris did not consistently validate storage locations supplied during table and view registration

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.

CVE-2026-64640
Unclassified
Aug 6, 2026
Medium6.5SonicWall

Medium [CVE-2026-0516] SonicOS: improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipu…

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

CVE-2026-0516
SonicOS Firewalls
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64579] preallocate inexact bins before xfrm_hash_rebuild reinsert

preallocate inexact bins before xfrm_hash_rebuild reinsert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64579
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64569] fix NULL deref in mpls_valid_fib_dump_req on CONFIG_INET=n

fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64569
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64574] tear down new links on vif update error path

tear down new links on vif update error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64574
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64567] reject free space cache with more entries than pages

reject free space cache with more entries than pages. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-64567
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64566] propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags

propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821.

CVE-2026-64566
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64571] validate RX frame length in p54_rx_eeprom_readback

validate RX frame length in p54_rx_eeprom_readback(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-64571
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64578] validate compound request size before reading StructureSize2

validate compound request size before reading StructureSize2. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-64578
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64575] fix double sock release on batch realloc

fix double sock release on batch realloc. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-64575
Unclassified
Aug 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-64576] initialize extack in nh_res_bucket_migrate

initialize extack in nh_res_bucket_migrate(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-64576
Unclassified
Aug 5, 2026