Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-64570] fix fils_discovery double free on alloc failure
fix fils_discovery double free on alloc failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9.
Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation
Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.
Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser
Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-8508] improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function
Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.
Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation
Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.
Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes
UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-67338] Stored cross-site scripting in Extension Manager allows arbitrary code execution
Stored cross-site scripting in Extension Manager allows arbitrary code execution. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-67290] Denial of Service via malformed media data
Denial of Service via malformed media data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Medium [CVE-2026-18321] Denial of Service via buffer overflow in Zyfer refclock
Denial of Service via buffer overflow in Zyfer refclock. Red Hat rates this low (CVSS 4.7). Weakness: CWE-120.
Medium [CVE-2026-17350] pgAdmin 4: Permission bypass allows authenticated users to access restricted tools
pgAdmin 4: Permission bypass allows authenticated users to access restricted tools. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-425.
Medium [CVE-2026-17348] pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-306.
Medium [CVE-2026-64607] Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Medium [CVE-2026-3276] Python Vulnerability in NetApp Products
Python versions through 3.13.13, 3.14.0 through 3.14.5, and 3.15.0a1 through 3.15.0b1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-42505] Golang Vulnerability in NetApp Products
Golang versions prior to 1.25.12, 1.26.0-0 prior to 1.26.5, and 1.27.0-0 prior to 1.27.0-rc.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-41839] Spring Framework Vulnerability in NetApp Products
Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-9828] Logback Vulnerability in NetApp Products
Logback versions prior to 1.5.33 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-12996] Denial of Service or memory leak via crafted packets
Denial of Service or memory leak via crafted packets. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.
Medium [CVE-2026-11771] Denial of Service via crafted NTLM proxy response
Denial of Service via crafted NTLM proxy response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787.