Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1921 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Zyxel

Medium [CVE-2026-8508] improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

CVE-2026-8508
Unclassified
Aug 4, 2026
Medium4.8Red Hat

Medium [CVE-2026-58044] Request smuggling via HTTP client header truncation

Request smuggling via HTTP client header truncation. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58044
Unclassified
Aug 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-58042] Denial of Service via DNS responses with excessive A records

Denial of Service via DNS responses with excessive A records. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58042
Unclassified
Aug 4, 2026
Medium6.2Red Hat

Medium [CVE-2026-58045] Denial of Service vulnerability

Denial of Service vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58045
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-58041] Node.js node:sqlite: Unintended data modification due to stale statement iterator

Node.js node:sqlite: Unintended data modification due to stale statement iterator. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:52990 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1, nodejs26-main-26.7.0-1.5.1.hum1.

CVE-2026-58041
Unclassified
Aug 4, 2026
Medium5.5Red Hat

Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.

CVE-2026-51400
Unclassified
Aug 4, 2026
Medium5.3Red Hat

Medium [CVE-2026-69198] Server-Side Request Forgery (SSRF) and trust-boundary bypass

Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana12-4-main-12.4.6-0.3.hum1.

CVE-2026-69198
Unclassified
Aug 3, 2026
Medium5.9Apache

Medium [CVE-2026-68979] Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.

CVE-2026-68979
NiFi
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18477] TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape

TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:49361 with package tar-main-1.35-9.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.

CVE-2026-18477
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-18651] SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account

SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287.

CVE-2026-18651
Unclassified
Aug 3, 2026
Medium4.4Red Hat

Medium [CVE-2026-18508] --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

- -one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:50807 with package tar-main-1.35-9.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.

CVE-2026-18508
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68742] NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR

NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-68742
Unclassified
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1

PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-68743
Unclassified
Aug 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation

Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12259
Unclassified
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-6695] remote code execution via crafted paa file

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-6695
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-6694] gimp file-png plugin: denial of service via oversized apng trns chunk

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. When processing a specially crafted APNG image, the plugin may crash due to a stack buffer overflow. As GIMP executes plugins in separate processes, the main application remains unaffected, limiting the impact to the plugin's functionality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-6694
Red Hat Enterprise Linux
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper

LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.

CVE-2026-59652
Unclassified
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-18573] Client access-type policy condition bypass during client update

Client access-type policy condition bypass during client update. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18573
Unclassified
Aug 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes

UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18572
Unclassified
Aug 2, 2026
Medium6.6Red Hat

Medium [CVE-2026-18571] FGAP V2 group assignment bypass during user creation

FGAP V2 group assignment bypass during user creation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862.

CVE-2026-18571
Unclassified
Aug 2, 2026