VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Arbitrary code execution via malformed XCOFF object file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`).
integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml". Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
fix crash due to unvalidated vcc pointer in sigd_send(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-822. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:33285 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via crafted symlinks in sandbox-expose options. Red Hat rates this important (CVSS 9). Weakness: CWE-59. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`).
Client authentication bypass in TLS 1.3 implementation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-166. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Certificate validation bypass due to incorrect certificate matching. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Unauthenticated remote code execution due to SSH command-line argument injection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:7383 — update the affected packages (`sudo dnf update`).
Use after free in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Use after free in Media. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Use after free in Blink. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Inappropriate implementation in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-641. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Integer overflow in Skia. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Out of bounds read and write in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Integer overflow in WebML. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-476. Affected package(s): openssl-main, rhui5/installer-rhel9:1781525693, openssl, compat-openssl10, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:35869 — update the affected packages (`sudo dnf update`).
Denial of Service and Information Disclosure via unauthenticated HTTP server. Red Hat rates this important (CVSS 8.2). Weakness: CWE-770. Affected package(s): rh-podman-desktop. Resolved in Red Hat advisory RHSA-2026:13867 — update the affected packages (`sudo dnf update`).
github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): multicluster-engine/hypershift-addon-rhel9-operator:1780917881. Resolved in Red Hat advisory RHSA-2026:25271 — update the affected packages (`sudo dnf update`).
Memory exhaustion via crafted compressed JWE tokens. Red Hat rates this low (CVSS 7.5). Weakness: CWE-770. Affected package(s): python3.12-jwcrypto, python-jwcrypto. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`).
Information disclosure via query parameter manipulation on the development server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-472. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1779783248. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`).
Information disclosure via WebSocket connection bypasses access control. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1220. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1779783248, automation-platform-ui, automation-gateway. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`).