VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Memory-safety vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. Affected package(s): advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630, rhtas/updatetree-rhel9:1780053572, rhtas/createtree-rhel9:1780053572, advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535, go-fdo-server. Resolved in Red Hat advisory RHSA-2026:13907 — update the affected packages (`sudo dnf update`).
Memory-safety vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. Affected package(s): advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630, rhtas/updatetree-rhel9:1780053572, rhtas/createtree-rhel9:1780053572, advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535, rhtas/trillian-logserver-rhel9:1780053572. Resolved in Red Hat advisory RHSA-2026:24482 — update the affected packages (`sudo dnf update`).
Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary Code Execution via specially crafted file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): LibRaw. Resolved in Red Hat advisory RHSA-2026:11360 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via specially crafted image file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): LibRaw. Resolved in Red Hat advisory RHSA-2026:13284 — update the affected packages (`sudo dnf update`).
Memory Corruption via Malicious File Processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): LibRaw. Resolved in Red Hat advisory RHSA-2026:13284 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via a specially crafted malicious file. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-190. Affected package(s): LibRaw. Resolved in Red Hat advisory RHSA-2026:11360 — update the affected packages (`sudo dnf update`).
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:11805 — update the affected packages (`sudo dnf update`).
Incorrect boundary conditions in the Graphics: WebGPU component. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Incorrect boundary conditions, integer overflow in the Graphics: Text component. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:11805 — update the affected packages (`sudo dnf update`).
Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:11805 — update the affected packages (`sudo dnf update`).
Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization. Red Hat rates this important (CVSS 7.4). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Erlang OTP public_key: OCSP authorization bypass and information disclosure due to missing signature verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
RCE via crafted discovery URI in Jolokia JMX-HTTP bridge. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Inappropriate implementation in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-130. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Authentication bypass and privilege escalation via OIDC userinfo cache key collision. Red Hat rates this important (CVSS 9.1). Weakness: CWE-222. Affected package(s): ansible-automation-platform, rhoai/odh-llama-stack-core-rhel9:1781826406, rhoai/odh-llama-stack-core-rhel9:1782310008. Resolved in Red Hat advisory RHSA-2026:28960 — update the affected packages (`sudo dnf update`).
Information disclosure via stale references after content deletion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524. Affected package(s): openshift4/ose-operator-lifecycle-manager:1781122773, openshift4/ose-operator-lifecycle-manager-rhel9:1779915499, openshift4/ose-operator-lifecycle-manager:1781123052, openshift4/ose-operator-lifecycle-manager:1781833795, openshift4/ose-operator-lifecycle-manager-rhel9:1780957268. Resolved in Red Hat advisory RHSA-2026:28893 — update the affected packages (`sudo dnf update`).