Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-62902] .NET: Information Disclosure Vulnerability
.NET: Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:44914 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet9-0-main-9.0.119-2.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-32791] Escalation of Privilege via Untrusted Search Path
Escalation of Privilege via Untrusted Search Path. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-426. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: pcm.
Medium [CVE-2025-31936] Privilege escalation via improper memory range handling in SMM
Privilege escalation via improper memory range handling in SMM. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: microcode_ctl.
Medium [CVE-2026-21399] Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow
Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120.
Medium [CVE-2026-20908] Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition
Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-20786] Denial of service via out-of-bounds read
Denial of service via out-of-bounds read. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-20783] Denial of Service via improper conditions check
Denial of Service via improper conditions check. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-606.
Medium [CVE-2026-20731] Denial of Service via Improper Buffer Restrictions
Denial of Service via Improper Buffer Restrictions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-131.
Medium [CVE-2026-73075] Out-of-bounds Access in Popup Opacity Handling
Out-of-bounds Access in Popup Opacity Handling. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125.
Medium [CVE-2026-73074] Heap buffer overflow via integer wraparound in text property handling
Heap buffer overflow via integer wraparound in text property handling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.
Medium [CVE-2026-19078] Open redirect vulnerability enables phishing via unvalidated parameter.
Open redirect vulnerability enables phishing via unvalidated parameter. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-14180] Undertow:HTTP request smuggling via oversized chunk-size bit overlap
Undertow:HTTP request smuggling via oversized chunk-size bit overlap. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 10; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 5 more.
Medium [CVE-2026-73070] Stack Buffer Overflow via unbounded socket connections
Stack Buffer Overflow via unbounded socket connections. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:56636 with package vim-main-9.2.967-1.hum1.
Medium [CVE-2026-71193] cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler
cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-71194] mDNS NOTIFY handler DoS via pool-blind zone lookup
mDNS NOTIFY handler DoS via pool-blind zone lookup. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-73067] Denial of Service due to crafted data model
Denial of Service due to crafted data model. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-72745] Information disclosure and memory corruption via malformed Kerberos GSS Wrap token
Information disclosure and memory corruption via malformed Kerberos GSS Wrap token. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-33922] Arbitrary file deletion via path traversal in Offline archives functionality
Arbitrary file deletion via path traversal in Offline archives functionality. Red Hat rates this moderate (CVSS 6). Weakness: CWE-22.
Medium [CVE-2026-33921] Information disclosure and arbitrary packet sending via insecure access restrictions
Information disclosure and arbitrary packet sending via insecure access restrictions. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-1188.
Medium [CVE-2026-71218] Unbounded peer-controlled allocation in iperf3 JSON_read allows unauthenticated remote memory exhaustion
Unbounded peer-controlled allocation in iperf3 JSON_read() allows unauthenticated remote memory exhaustion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-789. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.