VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
2035 advisories across 32 monitored vendors.
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-732. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
heap-based buffer overflow via specially crafted PSP file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:2953 — update the affected packages (`sudo dnf update`).
prevent potential out-of-bounds reads in handle_auth_done(). Red Hat rates this moderate (CVSS 7.1). Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`).
replace overzealous BUG_ON in osdmap_apply_incremental(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-617. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`).
Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Invalid memory access leading to potential arbitrary code execution via a crafted model file.. Red Hat rates this important (CVSS 7.8). Weakness: CWE-119. Affected package(s): rhoai/odh-openvino-model-server-rhel9:1772093351, rhoai/odh-training-cuda124-torch25-py311-rhel9:1772093260, rhoai/odh-training-cuda121-torch24-py311-rhel9:1772093252, rhoai/odh-openvino-model-server-rhel9:1771608633, rhoai/odh-training-rocm62-torch25-py311-rhel9:1772093324, rhoai/odh-training-rocm62-torch24-py311-rhel9:1772093338. Resolved in Red Hat advisory RHSA-2026:3713 — update the affected packages (`sudo dnf update`).
Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected package(s): devspaces/udi-rhel9:1774451954, rhtas/segment-reporting-rhel9:1770108732, ansible-automation-platform, rhoai/odh-training-rocm62-torch24-py311-rhel9:1772093338, quay/quay-rhel9:1770836901, rhoai/odh-training-cuda124-torch25-py311-rhel9:1772093260. Resolved in Red Hat advisory RHSA-2026:2139 — update the affected packages (`sudo dnf update`).
Denial of Service due to excessive recursion during object serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
denial of service vulnerability in parsePatch and applyPatch. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via large encoded array lengths. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via malicious regular expressions during deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary Code Execution via Improper JSON Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Prototype pollution via improper input validation during JSON deserialization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1321. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation and information disclosure via stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Cross-Namespace Secret Disclosure via `getSecretKey` Function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via untrusted model loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-gaudi-rhel9:1770956034. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
prototype pollution in _.unset and _.omit functions. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1321. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, openshift-gitops, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, openshift4/ose-console-rhel9:1770831186, multicluster-engine/console-mce-rhel9:1776223790. Resolved in Red Hat advisory RHSA-2026:3869 — update the affected packages (`sudo dnf update`).
Denial of Service via corrupt or malicious record. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`).
POP3 command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).
IMAP command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).