VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
2035 advisories across 32 monitored vendors.
Intel (R): From CVEorg collector. Red Hat rates this important (CVSS 7.9). Weakness: CWE-1220. Affected package(s): microcode_ctl. Resolved in Red Hat advisory RHSA-2026:6888 — update the affected packages (`sudo dnf update`).
Inappropriate implementation in WebGPU. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap buffer overflow in Codecs. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Axios affected by Denial of Service via __proto__ Key in mergeConfig. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, ansible-automation-platform, openshift-service-mesh/kiali-ossmc-rhel9:1771372942, rhoai/odh-dashboard-rhel9:1776742021. Resolved in Red Hat advisory RHSA-2026:3107 — update the affected packages (`sudo dnf update`).
Unauthorized Access via JWT authorization grant with disabled users. Red Hat rates this important (CVSS 8.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Disabled identity providers are still accepted for JWT Authorization Grant. Red Hat rates this important (CVSS 8.8). Weakness: CWE-358. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`).
Unauthorized organization registration via improper invitation token validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`).
Predictable UUIDs from randomness source errors can lead to security bypasses. Red Hat rates this important (CVSS 7.7). Weakness: CWE-331. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Denial of Service via crafted ClientHello with invalid PSK binder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): gnutls-main. Resolved in Red Hat advisory RHSA-2026:7477 — update the affected packages (`sudo dnf update`).
Blocklist evasion via ECDSA Signature Malleability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via 'helpfile' option processing. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim, rhui5/cds-rhel9:1776868774. Resolved in Red Hat advisory RHSA-2026:4715 — update the affected packages (`sudo dnf update`).
Information disclosure via Server-Side Request Forgery (SSRF) through malicious URLs in message history.. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary Code Execution via malicious custom template file during ebook conversion. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution via path traversal in CHM reader. Red Hat rates this important (CVSS 8.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file corruption via path traversal in EPUB conversion. Red Hat rates this important (CVSS 8.2). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution and information disclosure via path traversal in web UI. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution and file overwrite as root via insecure ast_coredumper file handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-379. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Incorrect certificate validation during TLS session resumption. Red Hat rates this moderate (CVSS 7.4). Affected package(s): openshift4/openshift-route-controller-manager-rhel8:1781867531, openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538, openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/oc-mirror-plugin-rhel8:1781822901, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`).
Go cgo: Code smuggling due to comment parsing discrepancy. Red Hat rates this important (CVSS 7.4). Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099, openshift4/ose-azure-file-csi-driver-operator-rhel9:1773363768, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345. Resolved in Red Hat advisory RHSA-2026:3469 — update the affected packages (`sudo dnf update`).
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak. Red Hat rates this important (CVSS 7.1). Weakness: CWE-367. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1772196222. Resolved in Red Hat advisory RHSA-2026:3960 — update the affected packages (`sudo dnf update`).