Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1Red Hat

High [CVE-2026-53790] rsync < 3.5.0 Command Injection via Multiple Code Paths

rsync < 3.5.0 Command Injection via Multiple Code Paths. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53790
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode

Arbitrary file write via path traversal in --relative mode. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53785
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat Updated

High [CVE-2026-53784] Unauthorized File Access via Symlink Module Root

Unauthorized File Access via Symlink Module Root. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53784
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53783] Directory escape via TOCTOU race condition in rrsync

Directory escape via TOCTOU race condition in rrsync. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: rsync.

CVE-2026-53783
Red Hat Enterprise Linux
Aug 13, 2026
High7.0Red Hat

High [CVE-2026-53803] Local Privilege Escalation via Symlink Following

Local Privilege Escalation via Symlink Following. Red Hat rates this important (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53803
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names

Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 3 more.

CVE-2026-73508
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73507] Denial of Service via CPU Exhaustion in XmlFrameDecoder

Denial of Service via CPU Exhaustion in XmlFrameDecoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Single Sign-On 7.

CVE-2026-73507
Unclassified
Aug 13, 2026
High7.8Red Hat

High [CVE-2026-73505] Arbitrary command execution via template injection in directory names

Arbitrary command execution via template injection in directory names. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-73505
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server

Denial of Service via unbounded memory growth in QUIC server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56097 with package openssl-main-3.5.6-0.5.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: openssl.

CVE-2026-14456
Red Hat Enterprise Linux
Aug 13, 2026
High7.7Red Hat

High [CVE-2026-66804] authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure

authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:57194 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, multicluster-engine/console-mce-rhel9:1786668856. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66804
Unclassified
Aug 13, 2026
High7.2Red Hat Updated

High [CVE-2026-6471] Arbitrary code execution via logical decoding plugin

Arbitrary code execution via logical decoding plugin. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-6471
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-14671] Arbitrary code execution via type confusion in 'refint' module

Arbitrary code execution via type confusion in 'refint' module. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14671
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-19385] PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. An authenticated object creator can exploit this by providing a specially crafted transform list. Attackers with object-creation privileges can use crafted function transform lists to run OS commands as the backup user. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-122. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:57198. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-19385
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-16239] Arbitrary code execution via type confusion in cursor lifecycle

Arbitrary code execution via type confusion in cursor lifecycle. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-16239
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-16238] Arbitrary code execution via type confusion in pg_restore_attribute_stats

Arbitrary code execution via type confusion in pg_restore_attribute_stats(). Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql18.

CVE-2026-16238
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat Updated

High [CVE-2026-15742] PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability in the PostgreSQL `fuzzystrmatch` extension is rated as Important. This risk is present only when the `fuzzystrmatch` extension is explicitly installed and utilized, as it is not enabled by default in Red Hat deployments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-15742
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-14680] Arbitrary code execution via type confusion with "internal" arguments

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This type confusion flaw bypasses intended security boundaries for 'internal' data types, leading to a significant privilege escalation and potential compromise of the entire database server. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14680
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat Updated

High [CVE-2026-14679] Stack buffer overflow via OUT parameter count manipulation

Stack buffer overflow via OUT parameter count manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14679
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-14677] Arbitrary code execution in 32-bit pltcl and plperl

Arbitrary code execution in 32-bit pltcl and plperl. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14677
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-14676] PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql18.

CVE-2026-14676
Red Hat Enterprise Linux
Aug 13, 2026