Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.9Red Hat

Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records

Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58042
Unclassified
Aug 4, 2026
Medium6.2Red Hat

Medium [CVE-2026-58045] Denial of Service vulnerability

Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58045
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator

Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58041
Unclassified
Aug 4, 2026
Medium5.5Red Hat

Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.

CVE-2026-51400
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-69198] Server-Side Request Forgery (SSRF) and trust-boundary bypass

Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana12-4-main-12.4.6-0.3.hum1.

CVE-2026-69198
Unclassified
Aug 3, 2026
Medium5.9Apache

Medium [CVE-2026-68979] Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.

CVE-2026-68979
NiFi
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18477] TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape

TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:49361 with package tar-main-1.35-9.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.

CVE-2026-18477
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-18651] SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account

SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287.

CVE-2026-18651
Unclassified
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18508] --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

- -one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:50807 with package tar-main-1.35-9.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.

CVE-2026-18508
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68742] NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR

NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-68742
Unclassified
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1

PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-68743
Unclassified
Aug 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation

Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12259
Unclassified
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper

LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.

CVE-2026-59652
Unclassified
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-18573] Client access-type policy condition bypass during client update

Client access-type policy condition bypass during client update. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18573
Unclassified
Aug 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes

UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18572
Unclassified
Aug 2, 2026
Medium6.6Red Hat

Medium [CVE-2026-18571] FGAP V2 group assignment bypass during user creation

FGAP V2 group assignment bypass during user creation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862.

CVE-2026-18571
Unclassified
Aug 2, 2026
Medium5.4Red Hat

Medium [CVE-2026-18570] Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed

Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18570
Unclassified
Aug 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-67302] Denial of service in camera redirection due to divide-by-zero

Denial of service in camera redirection due to divide-by-zero. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-369.

CVE-2026-67302
Unclassified
Aug 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-67306] Out-of-bounds read vulnerability via crafted RDP messages

Out-of-bounds read vulnerability via crafted RDP messages. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125.

CVE-2026-67306
Unclassified
Aug 1, 2026
Medium6.3Red Hat

Medium [CVE-2026-67295] Unauthorized File Access via Drive Redirection Vulnerability

Unauthorized File Access via Drive Redirection Vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22.

CVE-2026-67295
Unclassified
Aug 1, 2026