VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
2035 advisories across 32 monitored vendors.
Man-in-the-Middle vulnerability due to disabled certificate validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, python-pulp-container, python-pulp-rpm, python-django. Resolved in Red Hat advisory RHSA-2026:5971 — update the affected packages (`sudo dnf update`).
Man-in-the-Middle due to insecure default SSL verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Affected package(s): foreman, rubygem-katello, rubygem-foreman_kubevirt, rubygem-fog-kubevirt, python-pulp-container, python-pulp-rpm. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`).
Arbitrary file creation via path traversal bypass in hardlink security check. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, network-observability/network-observability-console-plugin-compat-rhel9:1771227610, eap7-wildfly, rhtas/rekor-search-ui-rhel9:1773308315, linux-sgx, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`).
OS command injection in the logfile variable in lib/Local.js. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Prototype Pollution vulnerability in the value function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): ansible-automation-platform/automation-portal:1770282458, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647, ansible-automation-platform/automation-portal:1770281704. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`).
Server-Side Request Forgery allows internal network access. Red Hat rates this important (CVSS 7.1). Weakness: CWE-918. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via unsafe deserialization of code coverage files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via malicious checkpoint file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`).
Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-121. Affected package(s): gnupg2. Resolved in Red Hat advisory RHSA-2026:2753 — update the affected packages (`sudo dnf update`).
Remote code execution and denial of service via crafted CMS EnvelopedData message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-121. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Use-after-free in the Layout: Scrolling and Overflow component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. Affected package(s): grafana, rhacm2/acm-grafana-rhel9:1774950654, rhacm2/acm-grafana-rhel9:1774002166. Resolved in Red Hat advisory RHSA-2026:2920 — update the affected packages (`sudo dnf update`).
Denial of Service via resource exhaustion from avatar requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363, rhoai/odh-vllm-gaudi-rhel9:1770956034, rhaiis/vllm-cuda-rhel9:1772160593, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`).
Arbitrary code execution due to out-of-bounds write in PKCS#12 processing. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-131. Affected package(s): jbcs-httpd24-mod_md, rhcos, jbcs-httpd24-mod_http2, rhui5/installer-rhel9:1770646925, jbcs-httpd24-mod_proxy_cluster, openssl-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`).
Denial of Service via specially crafted HTTP requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): com.github.streamshub-console. Resolved in Red Hat advisory RHSA-2026:13571 — update the affected packages (`sudo dnf update`).
fix possible UAF in macvlan_forward_source(). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3966 — update the affected packages (`sudo dnf update`).
Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:4723 — update the affected packages (`sudo dnf update`).
email header injection due to unquoted newlines. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-93. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).
Denial of Service due to recursion depth bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Affected package(s): protobuf, python3.12-protobuf, rhaiis/vllm-spyre-rhel9:1778244546, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-cuda-rhel9:1775680192. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`).