Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Red Hat Updated

High [CVE-2026-15679] Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data

Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-15679
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18309] Remote Code Execution via APNG file parsing integer overflow

Remote Code Execution via APNG file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: gimp.

CVE-2026-18309
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18308] Remote Code Execution via TIF File Parsing Integer Overflow

Remote Code Execution via TIF File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: gimp.

CVE-2026-18308
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18307] Remote code execution via TIF file parsing heap-based buffer overflow

Remote code execution via TIF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18307
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18306] Remote Code Execution via SGI File Parsing Integer Overflow

Remote Code Execution via SGI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18306
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18305] Remote Code Execution via TIF file parsing integer overflow

Remote Code Execution via TIF file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18305
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18304] Arbitrary code execution via crafted TIF file parsing

Arbitrary code execution via crafted TIF file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18304
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18303] Remote code execution via TIF file parsing vulnerability

Remote code execution via TIF file parsing vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18303
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18302] Remote code execution via TIF file parsing heap-based buffer overflow

Remote code execution via TIF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18302
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18301] Remote code execution via PSD file parsing integer overflow

Remote code execution via PSD file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18301
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18300] Remote code execution via integer overflow in HDR file parsing

Remote code execution via integer overflow in HDR file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: gimp; Red Hat package: gegl04.

CVE-2026-18300
Red Hat Enterprise Linux
Aug 20, 2026
High8.8Red Hat Updated

High [CVE-2026-18299] Remote Code Execution via Use-After-Free in rtpsbcdepay

Remote Code Execution via Use-After-Free in rtpsbcdepay. Red Hat rates this important (CVSS 8.8). Weakness: CWE-386. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.8, gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-18299
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18298] Remote code execution via heap-based buffer overflow in PNG file parsing

Remote code execution via heap-based buffer overflow in PNG file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7, gstreamer1-plugins-good-0:1.26.7-2.el10_2.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18298
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18297] Arbitrary code execution via OGG file parsing buffer overflow

Arbitrary code execution via OGG file parsing buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59097 with package gstreamer1-plugins-base-0:1.16.1-6.el8_10.1, gstreamer1-plugins-base-0:1.26.7-2.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18297
Unclassified
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-18296] Remote Code Execution via MRF file parsing heap-based buffer overflow

Remote Code Execution via MRF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7, gstreamer1-plugins-good-0:1.26.7-2.el10_2.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-18296
Unclassified
Aug 20, 2026
High8.8Red Hat Updated

High [CVE-2026-18295] Remote code execution via MRF file parsing

Remote code execution via MRF file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-18295
Unclassified
Aug 20, 2026
High8.1Red Hat

High [CVE-2026-77176] Insufficient validation of CreateContainer mount and storage rules in genpolicy

Insufficient validation of CreateContainer mount and storage rules in genpolicy. Red Hat rates this important (CVSS 8.1). Weakness: CWE-73. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-77176
Unclassified
Aug 20, 2026
High7.4Vendor: MediumRed Hat

High [CVE-2026-19611] Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access. This issue has Moderate impact. Successful exploitation depends on accounts using fullwidth or other NFKC-compatibility characters in passwords and on the feasibility of password guessing against the deployed hash algorithm. Red Hat severity: Moderate — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-173. Affected Red Hat products: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-19611
Unclassified
Aug 20, 2026
High8.2Red Hat Updated

High [CVE-2026-49825] URL bypass vulnerability in Cleaner via missing xlink:href

URL bypass vulnerability in Cleaner via missing xlink:href. Red Hat rates this important (CVSS 8.2). Weakness: CWE-166. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 20 more. Affected products named by the advisory: Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 16 more.

CVE-2026-49825
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat Updated

High [CVE-2026-61898] Arbitrary code execution via shell injection

Arbitrary code execution via shell injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-61898
Unclassified
Aug 20, 2026