Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1861 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Red Hat

Medium [CVE-2026-19012] Authenticated denial of service via configuration entry

Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19012
Red Hat Enterprise Linux
Aug 7, 2026
Medium4.2Red Hat

Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API

Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.

CVE-2026-19016
Red Hat Enterprise Linux
Aug 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges

Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.

CVE-2026-71852
Unclassified
Aug 7, 2026
Medium6.2Red Hat

Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems

Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.

CVE-2026-18938
Unclassified
Aug 7, 2026
Medium4.4Red Hat

Medium [CVE-2026-19079] toctou race condition in fixfiles allows arbitrary selinux label manipulation

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow. Red Hat ships policycoreutils with the fixfiles script in all supported RHEL versions. The vulnerable /tmp cleanup code path has been present in fixfiles for many years. Red Hat product impact analysis is required to determine which specific shipped versions of policycoreutils include the vulnerable code and whether backporting the upstream fix is necessary. The vulnerability requires local access, winning a race condition, and an administrator running fixfiles relabel or fixfiles restore, which limits the practical attack surface. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-367.

CVE-2026-19079
Red Hat Enterprise Linux
Aug 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction

Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12261
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-63140] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.0.0 through 8.19.18, 9.0.0 through 9.3.7, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63140
Unclassified
Aug 7, 2026
Medium6.7NetApp

Medium [CVE-2026-15370] Libssh Vulnerability in NetApp Products

Libssh versions 0.11.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-15370
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-56145] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.19.0 through 8.19.17, 9.3.0 through 9.3.6, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-56145
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-63144] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.19.0 through 8.19.18, 9.3.0 through 9.3.7, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63144
Unclassified
Aug 7, 2026
Medium5.3NetApp

Medium [CVE-2026-56144] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.12.0 through 8.19.17, 9.0.0 through 9.3.6, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-56144
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-59844] Libssh Vulnerability in NetApp Products

Libssh versions prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59844
Unclassified
Aug 7, 2026
Medium6.9NetApp

Medium [CVE-2026-53655] Tar Vulnerability in NetApp Products

Tar (node-tar) versions prior to 7.5.16 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-53655
AFF / ASA / FASElement Software
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-59845] Libssh Vulnerability in NetApp Products

Libssh versions 0.9.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59845
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-59847] Libssh Vulnerability in NetApp Products

Libssh versions 0.9.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59847
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-63136] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.0.0 through 8.19.14, 9.0.0 through 9.2.8, and 9.3.0 through 9.3.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63136
Unclassified
Aug 7, 2026
Medium4.2VMware

Medium [CVE-2026-41861] BOSH: Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file wi…

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in.network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").

CVE-2026-41861
Tanzu / Spring
Aug 6, 2026
Medium5.1Red Hat

Medium [CVE-2026-71498] Information disclosure via out-of-bounds read with malformed UTF-8 input

Information disclosure via out-of-bounds read with malformed UTF-8 input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-125.

CVE-2026-71498
Unclassified
Aug 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-70631] Information disclosure via uninitialized heap memory read in TIFF decoder

Information disclosure via uninitialized heap memory read in TIFF decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-70631
Unclassified
Aug 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-70630] Information disclosure via uninitialized heap memory read in Screenpresso decoder

Information disclosure via uninitialized heap memory read in Screenpresso decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824.

CVE-2026-70630
Unclassified
Aug 6, 2026