Complete feed
Security advisories & CVEs
1914 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-64578] validate compound request size before reading StructureSize2
validate compound request size before reading StructureSize2. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64575] fix double sock release on batch realloc
fix double sock release on batch realloc. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-64576] initialize extack in nh_res_bucket_migrate
initialize extack in nh_res_bucket_migrate(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64570] fix fils_discovery double free on alloc failure
fix fils_discovery double free on alloc failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9.
Medium [CVE-2026-18103] Persistent denial of service due to buffer overflow via OMAPI
Persistent denial of service due to buffer overflow via OMAPI. Red Hat rates this low (CVSS 4.9). Weakness: CWE-120.
Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation
Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.
Medium [CVE-2026-15920] Cross-site scripting via unvalidated URLField values in the admin
Cross-site scripting via unvalidated URLField values in the admin. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.
Medium [CVE-2026-15830] Denial of Service via parsing deeply nested geometry collections
Denial of Service via parsing deeply nested geometry collections. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-606.
Medium [CVE-2026-15337] Denial-of-service vulnerability due to excessive memory consumption
Denial-of-service vulnerability due to excessive memory consumption. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050.
Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser
Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-70368] Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-70367] SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services
SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-918. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-17614] Path Traversal on WildFly Domain Controller
Path Traversal on WildFly Domain Controller. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22.
Medium [CVE-2026-8508] improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Medium [CVE-2026-58044] Request smuggling via HTTP client header truncation
Request smuggling via HTTP client header truncation. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.
Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records
Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.
Medium [CVE-2026-58045] Denial of Service vulnerability
Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.
Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator
Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.
Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function
Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.
Medium [CVE-2026-69198] Server-Side Request Forgery (SSRF) and trust-boundary bypass
Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana12-4-main-12.4.6-0.3.hum1.