Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8Red Hat

High [CVE-2026-42170] GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer (ddsread.c)

GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c). Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-42170
Unclassified
Aug 4, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64561] Check for invalid/obsolete root *after* making MMU pages available

Check for invalid/obsolete root *after* making MMU pages available. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45192 with package kernel-0:5.14.0-687.30.1.el9_8, kernel-0:6.12.0-55.94.1.el10_0, kernel-0:4.18.0-553.147.1.el8_10, kernel-0:5.14.0-427.141.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-64561
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67855] Denial of Service via heap use-after-free

Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-67855
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function

Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-67857
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-51401] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this important (CVSS 7.8). Weakness: CWE-641.

CVE-2026-51401
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server

Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67858
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67859] Denial of Service via Discovery/LDS handling

Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67859
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67862] Denial of Service via buffer-overflow

Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67862
Unclassified
Aug 4, 2026
High8.1Red Hat

High [CVE-2026-8400] Arbitrary class loading and instantiation via malicious IIOP server

Arbitrary class loading and instantiation via malicious IIOP server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-470. Red Hat lists fixing advisory RHSA-2026:52949 with package java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-8400
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing

don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.

CVE-2026-64564
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component

Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-67861
Unclassified
Aug 4, 2026
High8.2Red Hat

High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path

Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.

CVE-2026-67860
Unclassified
Aug 4, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-69240] SQL Injection via improper handling of Oracle date functions

SQL Injection via improper handling of Oracle date functions. Red Hat rates this important (CVSS 9.8). Weakness: CWE-89. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Satellite 6.

CVE-2026-69240
Unclassified
Aug 3, 2026
Critical9.3Check Point Exploited

Critical [CVE-2026-18574] authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

CVE-2026-18574
Security Management
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-69244] Denial of Service via malformed HTTP responses

Denial of Service via malformed HTTP responses. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55853 with package ansible-automation-platform/ee-minimal-rhel8:1786971288, ansible-automation-platform/ee-minimal-rhel9:1786942232, discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.

CVE-2026-69244
Unclassified
Aug 3, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-69243] HTTP Request Smuggling via WebSocket Upgrade

HTTP Request Smuggling via WebSocket Upgrade. Red Hat rates this moderate (CVSS 7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54760 with package discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.

CVE-2026-69243
Unclassified
Aug 3, 2026
High8.8Apache

High [CVE-2026-68981] Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

CVE-2026-68981
NiFi
Aug 3, 2026
High7.7Apache

High [CVE-2026-62354] Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.

CVE-2026-62354
NiFi
Aug 3, 2026
High8.6Red Hat

High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this important (CVSS 8.6). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:56338 with package nodejs24-1:24.18.0-5.el10_2, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.2-0.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-69192
Unclassified
Aug 3, 2026
High7.5Red Hat

High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets

Denial of Service via memory exhaustion from crafted packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-69185
Unclassified
Aug 3, 2026