Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1869 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.9NetApp

Medium [CVE-2026-53655] Tar Vulnerability in NetApp Products

Tar (node-tar) versions prior to 7.5.16 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-53655
AFF / ASA / FASElement Software
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-59845] Libssh Vulnerability in NetApp Products

Libssh versions 0.9.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59845
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-59847] Libssh Vulnerability in NetApp Products

Libssh versions 0.9.0 prior to 0.11.5 and prior to 0.12.1 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59847
Unclassified
Aug 7, 2026
Medium6.5NetApp

Medium [CVE-2026-63136] Elasticsearch Vulnerability in NetApp Products

Elasticsearch versions 8.0.0 through 8.19.14, 9.0.0 through 9.2.8, and 9.3.0 through 9.3.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63136
Unclassified
Aug 7, 2026
Medium4.2VMware

Medium [CVE-2026-41861] BOSH: Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file wi…

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in.network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").

CVE-2026-41861
Tanzu / Spring
Aug 6, 2026
Medium5.1Red Hat

Medium [CVE-2026-71498] Information disclosure via out-of-bounds read with malformed UTF-8 input

Information disclosure via out-of-bounds read with malformed UTF-8 input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-125.

CVE-2026-71498
Unclassified
Aug 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-70631] Information disclosure via uninitialized heap memory read in TIFF decoder

Information disclosure via uninitialized heap memory read in TIFF decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-70631
Unclassified
Aug 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-70630] Information disclosure via uninitialized heap memory read in Screenpresso decoder

Information disclosure via uninitialized heap memory read in Screenpresso decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824.

CVE-2026-70630
Unclassified
Aug 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-70629] Information disclosure via uninitialized heap memory read in RSCC decoder

Information disclosure via uninitialized heap memory read in RSCC decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-70629
Unclassified
Aug 6, 2026
Medium4.7Red Hat

Medium [CVE-2026-71497] Cross-site scripting via malformed HTML tag names

Cross-site scripting via malformed HTML tag names. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-1289. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Applications 8; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; and 12 more. Affected products named by the advisory: Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Quarkus Native builder; Red Hat Enterprise Linux 10; and 8 more.

CVE-2026-71497
Unclassified
Aug 6, 2026
Medium5.3Red Hat

Medium [CVE-2026-61632] Information disclosure via path traversal in b64 extension

Information disclosure via path traversal in b64 extension. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Developer Hub; Red Hat OpenShift Container Platform 4; Self-service automation portal 2.

CVE-2026-61632
Unclassified
Aug 6, 2026
Medium6.8Red Hat

Medium [CVE-2026-19167] Cross-origin data leakage via integer overflow in GPU

Cross-origin data leakage via integer overflow in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190.

CVE-2026-19167
Unclassified
Aug 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-19146] Google Chrome (Android): Information disclosure via uninitialized GPU memory use

Google Chrome (Android): Information disclosure via uninitialized GPU memory use. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824.

CVE-2026-19146
Unclassified
Aug 6, 2026
Medium6.7Red Hat

Medium [CVE-2026-19139] OS-level privilege escalation due to a race condition via a malicious file

OS-level privilege escalation due to a race condition via a malicious file. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367.

CVE-2026-19139
Unclassified
Aug 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-71439] Denial of Service via Radar Diagrams 'ticks' parameter

Denial of Service via Radar Diagrams 'ticks' parameter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1050.

CVE-2026-71439
Unclassified
Aug 6, 2026
Medium4.0Red Hat

Medium [CVE-2026-71438] Prototype pollution vulnerability via configuration APIs

Prototype pollution vulnerability via configuration APIs. Red Hat rates this moderate (CVSS 4). Weakness: CWE-915. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-71438
Unclassified
Aug 6, 2026
Medium4.3Red Hat

Medium [CVE-2026-50159] CSS injection allows altering page elements via diagram input

CSS injection allows altering page elements via diagram input. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-79.

CVE-2026-50159
Unclassified
Aug 6, 2026
Medium5.4Red Hat

Medium [CVE-2026-71437] Prototype pollution vulnerability allows potential arbitrary code execution

Prototype pollution vulnerability allows potential arbitrary code execution. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-915.

CVE-2026-71437
Unclassified
Aug 6, 2026
Medium6.7Red Hat

Medium [CVE-2026-64654] Terminal escape sequence injection allows command execution

Terminal escape sequence injection allows command execution. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.

CVE-2026-64654
Unclassified
Aug 6, 2026
Medium5.4Red Hat

Medium [CVE-2026-64653] Path traversal via unescaped URL variables

Path traversal via unescaped URL variables. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-22.

CVE-2026-64653
Unclassified
Aug 6, 2026