VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`).
X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-191. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`).
Denial of Service and buffer overflow via crafted ECDH ciphertext. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-131. Affected package(s): libgcrypt-main. Resolved in Red Hat advisory RHSA-2026:8466 — update the affected packages (`sudo dnf update`).
Luanti (Minetest): Arbitrary code execution and full filesystem access via malicious mod sandbox escape. Red Hat rates this important (CVSS 8.2). Weakness: CWE-749. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
fix ro->uniq use-after-free in raw_rcv(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-366. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25095 — update the affected packages (`sudo dnf update`).
Unauthorized access to administrative functions through unauthenticated Remote Control endpoint.. Red Hat rates this important (CVSS 9.8). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file write inside guest image via CopyFile policy. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1220. Affected package(s): rhcos. Resolved in Red Hat advisory RHSA-2026:25200 — update the affected packages (`sudo dnf update`).
race condition vulnerability leads to arbitrary package installation as root. Red Hat rates this important (CVSS 8.8). Weakness: CWE-367. Affected package(s): PackageKit. Resolved in Red Hat advisory RHSA-2026:11504 — update the affected packages (`sudo dnf update`).
Authentication bypass due to missing mutual authentication verification. Red Hat rates this important (CVSS 7.3). Weakness: CWE-325. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Authorization bypass due to incorrect servlet path matching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
User impersonation via malformed X.509 certificate Common Name (CN) values. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Do not skip unrelated mode changes in DSC validation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1288. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`).
Avoid releasing netdev before teardown completes. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:25217 — update the affected packages (`sudo dnf update`).
fix tx.buf use-after-free in isotp_sendmsg(). Red Hat rates this important (CVSS 7.8). Weakness: CWE-364. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`).
algif_aead - Revert to operating out-of-place. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1288. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:13729 — update the affected packages (`sudo dnf update`).
Privilege escalation via improper cryptographic signature verification. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Authentication bypass due to spoofed X-Forwarded-Uri header. Red Hat rates this important (CVSS 8.7). Weakness: CWE-290. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution and secret exfiltration via malicious git commands. Red Hat rates this important (CVSS 8.5). Weakness: CWE-88. Affected package(s): openshift-pipelines/pipelines-rhel9-operator:1780645012, serve-tkn-cli, openshift-builds/openshift-builds-image-processing-rhel9:1778682932, openshift-builds/openshift-builds-image-processing-rhel9:1780373835, openshift-builds/openshift-builds-git-cloner-rhel9:1780374151, openshift-builds/openshift-builds-image-bundler-rhel9:1780373867. Resolved in Red Hat advisory RHSA-2026:24484 — update the affected packages (`sudo dnf update`).
Critical data compromise and loss via SQL injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Enhance Path Factories Redux (Oracle CPU 2026-04). Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`).