VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Use-after-free in the Layout: Text and Fonts component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Incorrect boundary conditions in the Audio/Video: Playback component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-823. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Incorrect boundary conditions, integer overflow in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Use-after-free in the CSS Parsing and Computation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Sandbox escape in the Responsive Design Mode component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Sandbox escape due to use-after-free in the Disability Access APIs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Sandbox escape due to incorrect boundary conditions in the Telemetry component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-501. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Incorrect boundary conditions in the Graphics: Canvas2D component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
Race condition, use-after-free in the Graphics: WebRender component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-364. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`).
buffer overflows on response messages via ipmi-oem. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-120. Affected package(s): freeipmi. Resolved in Red Hat advisory RHSA-2026:19208 — update the affected packages (`sudo dnf update`).
Information disclosure via path traversal in git resolver. Red Hat rates this important (CVSS 9.6). Weakness: CWE-22. Affected package(s): openshift-builds/openshift-builds-rhel9-operator:1776860241, serve-tkn-cli, openshift-pipelines/pipelines-resolvers-rhel9:1774556280, openshift-pipelines/pipelines-resolvers-rhel9:1774596617, openshift-builds/openshift-builds-rhel9-operator:1776859898, openshift-pipelines/pipelines-operator-bundle:1776925111. Resolved in Red Hat advisory RHSA-2026:21932 — update the affected packages (`sudo dnf update`).
Private key recovery via incomplete comparison checks biasing DSA nonces. Red Hat rates this important (CVSS 9.1). Weakness: CWE-338. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`).
Use after free in WebGPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Integer overflow in Fonts. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote tool execution via cross-site request forgery. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-940. Affected package(s): devspaces/udi-rhel9:1779829736. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`).
Active Storage (Rails): Arbitrary file access via path traversal in blob keys. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution or Denial of Service via spurious IPC API call data. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-1287. Affected package(s): systemd, rhosdt/opentelemetry-collector-rhel9:1778056267, rhui5/haproxy-rhel9:1779798164, rhosdt/opentelemetry-rhel9-operator:1778056233, rhui5/rhua-rhel9:1779798222, insights-proxy/insights-proxy-container-rhel9:1780420428. Resolved in Red Hat advisory RHSA-2026:14162 — update the affected packages (`sudo dnf update`).
Private Key Recovery via Missing Cryptographic Step in DSA Signing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-325. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`).