| | CVE-2025-57849 | Red Hat | medium | 6.4 | A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /e… | Mar 13, 2026 | Mar 13, 2026 |
| | CVE-2025-8766 | Red Hat | high | 6.4 | A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. T… | Mar 13, 2026 | Mar 13, 2026 |
| | CVE-2026-4105 | Red Hat | medium | 7.8 | A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulner… | Mar 13, 2026 | Mar 13, 2026 |
| | CVE-2026-32597 | Red Hat | high | 7.5 | A missing verification step has been discovered in PyJWT. PyJWT does not validate the crit (Critical… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-2229 | Red Hat | high | 7.5 | A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerab… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-1528 | Red Hat | high | 7.5 | A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a speciall… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-1527 | Red Hat | medium | 6.5 | A flaw was found in undici, a Node.js HTTP/1.1 client. This vulnerability allows a remote attacker t… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32249 | Check Point | medium | 5.3 | Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex c… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-2581 | Red Hat | medium | 5.9 | A flaw was found in Undici. When the `interceptors.deduplicate()` feature is enabled, response data … | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-1526 | Red Hat | high | 7.5 | A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially … | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-1525 | Red Hat | medium | 6.5 | A flaw was found in undici, a Node.js HTTP/1.1 client. A remote attacker could exploit this vulnerab… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32274 | Red Hat | high | 7.5 | A user input sanitization flaw has been discovered in the Black python code formatter. Black writes … | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32237 | Red Hat | medium | 4.4 | A data exposure flaw has been discovered in the @backstage/plugin-scaffolder-backend npm library. Au… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32236 | Red Hat | medium | 0.0 | A server side request forgery flaw has been discovered in the npm @backstage/plugin-auth-backend pac… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32235 | Red Hat | medium | 5.9 | An allowlist bypass flaw has been discovered in the npm @backstage/plugin-auth-backend package. Inst… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-3497 | Red Hat | high | 8.2 | A flaw was found in the OpenSSH GSSAPI (Generic Security Service Application Program Interface) delt… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-32141 | Red Hat | high | 7.5 | A denial of service flaw has been discovered in the flatted npm library. flatted's parse() function … | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-21708 | Veeam | critical | 10.0 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user… | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21672 | Veeam | high | 8.8 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication serv… | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21668 | Veeam | high | 8.8 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrar… | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21669 | Veeam | critical | 10.0 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the … | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21671 | Veeam | critical | 9.1 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote … | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21666 | Veeam | critical | 10.0 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the … | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2026-21667 | Veeam | critical | 10.0 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the … | Mar 12, 2026 | Mar 13, 2026 |
| | CVE-2025-70873 | Red Hat | low | 3.3 | A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile exte… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-3909 | Red Hat | high | 8.8 | An out of bounds write flaw was found in the Skia component of the Chromium browser.
Upstream bug(s)… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-3910 | Red Hat | high | 8.8 | An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream… | Mar 12, 2026 | Mar 12, 2026 |
| | CVE-2026-3963 | Apache | low | 3.7 | A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-2808 | Red Hat | medium | 6.8 | A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privi… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-32117 | Grafana | high | 7.6 | The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-31979 | Microsoft | high | 8.8 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and … | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-31957 | Microsoft | critical | 10.0 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to befor… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-31958 | Red Hat | medium | 5.3 | A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a sp… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3950 | Red Hat | low | 3.3 | A flaw was found in libheif. A local attacker could exploit an out-of-bounds read vulnerability in t… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3949 | Red Hat | low | 3.3 | A flaw was found in libheif. This vulnerability allows a local attacker to trigger an out-of-bounds … | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-31870 | Red Hat | high | 7.5 | A flaw was found in cpp-httplib. A remote attacker, acting as a malicious server or through a man-in… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-30226 | Red Hat | medium | 5.9 | A flaw was found in the Svelte devalue JavaScript library. A remote attacker could exploit a prototy… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-20166 | Splunk | medium | 5.4 | In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20165 | Splunk | medium | 6.3 | In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform ver… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20164 | Splunk | medium | 6.5 | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform ver… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20163 | Splunk | high | 7.2 | In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform ver… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20162 | Splunk | medium | 6.3 | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform vers… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20118 | Cisco | medium | 6.8 | A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Ci… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20117 | Cisco | medium | 6.1 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20116 | Cisco | medium | 6.1 | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20074 | Cisco | high | 7.4 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing fea… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20046 | Cisco | high | 8.8 | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could a… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-20040 | Cisco | high | 8.8 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to … | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2025-68623 | Microsoft | high | 8.8 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-31853 | Red Hat | medium | 5.5 | A flaw was found in ImageMagick. An overflow on 32-bit systems in the SFW decoder can lead to a cras… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-1471 | Red Hat | low | 4.2 | A flaw was found in Neo4j. Authenticated users can inherit the authentication context of the first u… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2025-12690 | Forcepoint | medium | — | Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.Th… | Mar 11, 2026 | Mar 12, 2026 |
| | CVE-2026-29777 | Red Hat | medium | 6.8 | A flaw was found in Traefik. A tenant with write access to an HTTPRoute resource can exploit this vu… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-31892 | Red Hat | high | 9.9 | A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security s… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-28229 | Red Hat | high | 7.5 | A flaw was found in Argo Workflows in which an attacker can leak sensitive information contained in … | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3904 | Red Hat | medium | 5.9 | A flaw was found in glibc. When calling NSS-backed functions that support caching via nscd, the nscd… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3805 | Red Hat | medium | 6.3 | A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3784 | Red Hat | medium | 6.5 | A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy con… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3783 | Red Hat | medium | 5.7 | A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-1965 | Red Hat | medium | 6.8 | A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated … | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-3911 | Red Hat | low | 2.7 | A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnera… | Mar 11, 2026 | Mar 11, 2026 |
| | CVE-2026-31838 | Red Hat | medium | 5.3 | A flaw was found in Istio. This vulnerability in Envoy's Role-Based Access Control (RBAC) header mat… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-31837 | Red Hat | high | 7.5 | A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-31826 | Red Hat | medium | 6.5 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-31812 | Red Hat | high | 5.3 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-31808 | Red Hat | medium | 5.3 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-30951 | Red Hat | high | 7.5 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-26123 | Microsoft | medium | 5.5 | Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose … | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-23868 | Red Hat | high | 7.0 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-28292 | Red Hat | high | 8.8 | A vulnerability was discovered in the simple-git Node.js library. The issue is caused by improper va… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-30897 | Fortinet | medium | 6.6 | A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-26144 | Microsoft | high | 7.5 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26134 | Microsoft | high | 7.8 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileg… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26114 | Microsoft | high | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26113 | Microsoft | high | 8.4 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26112 | Microsoft | high | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26110 | Microsoft | high | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26109 | Microsoft | high | 8.4 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26108 | Microsoft | high | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26107 | Microsoft | high | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26106 | Microsoft | high | 8.8 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-26105 | Microsoft | high | 8.1 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25972 | Fortinet | medium | 4.3 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-25836 | Fortinet | high | 7.2 | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25689 | Fortinet | medium | 6.5 | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability … | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25180 | Microsoft | medium | 5.5 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose infor… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25169 | Microsoft | medium | 6.2 | Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25168 | Microsoft | medium | 6.2 | Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-25167 | Microsoft | high | 7.4 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privile… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-24641 | Fortinet | low | 2.7 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through … | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-24640 | Fortinet | medium | 6.6 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 throu… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-24018 | Fortinet | high | 7.8 | A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-24017 | Fortinet | high | 8.1 | An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet Forti… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-23668 | Microsoft | high | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Micro… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-22629 | Fortinet | low | 3.7 | An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-22628 | Fortinet | medium | 5.3 | An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allo… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-22627 | Fortinet | high | 8.8 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet F… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-22572 | Fortinet | high | 7.2 | An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer … | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-68648 | Fortinet | high | 7.2 | A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2025-68482 | Fortinet | medium | 6.9 | A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, Forti… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-66178 | Fortinet | high | 7.2 | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-55717 | Fortinet | medium | 4.0 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet Forti… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-54820 | Fortinet | high | 8.1 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 t… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-54659 | Fortinet | medium | 5.8 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2025-53608 | Fortinet | medium | 4.8 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-49784 | Fortinet | medium | 6.0 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-48840 | Fortinet | medium | 5.3 | An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWe… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2025-48418 | Fortinet | medium | 6.7 | A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.… | Mar 10, 2026 | Mar 12, 2026 |
| | CVE-2026-26130 | Red Hat | high | 7.5 | A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized attacker to perform a De… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-26127 | Red Hat | medium | 7.5 | A flaw was found in .NET. An unauthorized attacker can exploit an out-of-bounds read vulnerability o… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-26131 | Red Hat | medium | 7.8 | A flaw was found in .NET. Incorrect default permissions allow an authorized local attacker to exploi… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-30942 | Red Hat | high | 6.5 | A flaw was found in Flare, a file sharing platform. An authenticated path traversal vulnerability ex… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-2742 | Red Hat | medium | 6.3 | An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-2741 | Red Hat | low | 2.6 | Specially crafted ZIP archives can escape the intended extraction directory during Node.js download … | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-23907 | Red Hat | medium | 5.4 | A Path Traversal flaw was found in the `ExtractEmbeddedFiles` example within Apache PDFBox. An attac… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-28691 | Check Point | high | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-1776 | F5 | medium | — | Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulne… | Mar 10, 2026 | Mar 11, 2026 |
| | CVE-2026-23239 | Red Hat | high | 7.0 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-23240 | Red Hat | high | 7.0 | No description is available for this CVE. | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3918 | Red Hat | high | 8.8 | An use after free flaw was found in the WebMCP component of the Chromium browser.
Upstream bug(s):
h… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3921 | Red Hat | high | 8.8 | An use after free flaw was found in the TextEncoding component of the Chromium browser.
Upstream bug… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3913 | Red Hat | critical | 9.6 | A heap buffer overflow flaw was found in the WebML component of the Chromium browser.
Upstream bug(s… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3923 | Red Hat | high | 8.8 | An use after free flaw was found in the WebMIDI component of the Chromium browser.
Upstream bug(s):
… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3914 | Red Hat | high | 8.8 | An integer overflow flaw was found in the WebML component of the Chromium browser.
Upstream bug(s):
… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3938 | Red Hat | low | 4.3 | An insufficient policy enforcement flaw was found in the Clipboard component of the Chromium browser… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3934 | Red Hat | medium | 6.5 | An insufficient policy enforcement flaw was found in the ChromeDriver component of the Chromium brow… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3942 | Red Hat | low | 4.3 | An incorrect security ui flaw was found in the PictureInPicture component of the Chromium browser.
U… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3919 | Red Hat | high | 8.8 | An use after free flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3916 | Red Hat | high | 8.8 | An out of bounds read flaw was found in the Web Speech component of the Chromium browser.
Upstream b… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3915 | Red Hat | high | 8.8 | A heap buffer overflow flaw was found in the WebML component of the Chromium browser.
Upstream bug(s… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3927 | Red Hat | medium | 6.5 | An incorrect security ui flaw was found in the PictureInPicture component of the Chromium browser.
U… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3926 | Red Hat | medium | 6.5 | An out of bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
h… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3940 | Red Hat | low | 4.3 | An insufficient policy enforcement flaw was found in the DevTools component of the Chromium browser.… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3917 | Red Hat | high | 8.8 | An use after free flaw was found in the Agents component of the Chromium browser.
Upstream bug(s):
h… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3941 | Red Hat | low | 4.3 | An insufficient policy enforcement flaw was found in the DevTools component of the Chromium browser.… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3920 | Red Hat | high | 8.8 | An out of bounds memory access flaw was found in the WebML component of the Chromium browser.
Upstre… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3928 | Red Hat | medium | 6.5 | An insufficient policy enforcement flaw was found in the Extensions component of the Chromium browse… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3922 | Red Hat | high | 8.8 | An use after free flaw was found in the MediaStream component of the Chromium browser.
Upstream bug(… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3931 | Red Hat | medium | 6.5 | A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s)… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3929 | Red Hat | medium | 6.5 | A side-channel information leakage flaw was found in the ResourceTiming component of the Chromium br… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3924 | Red Hat | high | 8.8 | An use after free flaw was found in the WindowDialog component of the Chromium browser.
Upstream bug… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3935 | Red Hat | medium | 6.5 | An incorrect security ui flaw was found in the WebAppInstalls component of the Chromium browser.
Ups… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3939 | Red Hat | low | 4.3 | An insufficient policy enforcement flaw was found in the PDF component of the Chromium browser.
Upst… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-3930 | Red Hat | medium | 6.5 | An unsafe navigation flaw was found in the Navigation component of the Chromium browser.
Upstream bu… | Mar 10, 2026 | Mar 10, 2026 |
| | CVE-2026-30937 | Red Hat | medium | 6.8 | A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. An in… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-30936 | Red Hat | medium | 5.5 | A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digita… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-30935 | Red Hat | medium | 5.5 | A flaw was found in ImageMagick. Processing a specially crafted image with the -bilateral-blur opera… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-30931 | Red Hat | medium | 6.8 | A flaw was found in ImageMagick, a software used for editing and manipulating digital images. A loca… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-30929 | Red Hat | medium | 6.1 | A flaw was found in ImageMagick. Processing a specially crafted image with the MagnifyImage function… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-30883 | Red Hat | medium | 5.7 | A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating d… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28693 | Red Hat | high | 8.1 | A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating d… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28692 | Red Hat | medium | 4.8 | A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating d… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28691 | Red Hat | high | 7.5 | No description is available for this CVE. | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28690 | Red Hat | medium | 6.1 | A flaw was found in ImageMagick. Processing a specially crafted image with the MNG encoder can cause… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28689 | Red Hat | medium | 6.3 | A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating d… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28688 | Red Hat | medium | 5.5 | A flaw was found in ImageMagick. Processing commands related to MSL writing, specifically cloning an… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28687 | Red Hat | medium | 5.3 | A flaw was found in ImageMagick, free and open-source software used for editing and manipulating dig… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28686 | Red Hat | medium | 6.8 | A flaw was found in ImageMagick, free and open-source software used for editing and manipulating dig… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28494 | Red Hat | medium | 7.1 | A flaw was found in ImageMagick. This vulnerability, a stack buffer overflow, allows an attacker to … | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-28493 | Red Hat | medium | 6.5 | A flaw was found in ImageMagick. An integer overflow vulnerability exists in the SIXEL decoder, whic… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-31802 | Red Hat | medium | 6.2 | No description is available for this CVE. | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-25960 | Red Hat | high | 7.1 | A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). A remote… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-0846 | Red Hat | high | 7.5 | A flaw was found in the `nltk` component. This vulnerability, specifically within the `filestring()`… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-24713 | Apache | critical | 9.8 | Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.… | Mar 9, 2026 | Mar 10, 2026 |
| | CVE-2026-24015 | Apache | critical | 9.8 | A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0… | Mar 9, 2026 | Mar 10, 2026 |
| | CVE-2025-69647 | Red Hat | low | 3.3 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafte… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2025-69648 | Red Hat | low | 3.3 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafte… | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2024-14027 | Red Hat | low | 5.5 | No description is available for this CVE. | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2025-70034 | Red Hat | medium | 6.5 | An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in … | Mar 9, 2026 | Mar 9, 2026 |
| | CVE-2026-3731 | Red Hat | medium | 5.3 | A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_ext… | Mar 8, 2026 | Mar 8, 2026 |
| | CVE-2026-3713 | Red Hat | medium | 5.3 | A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the functio… | Mar 8, 2026 | Mar 8, 2026 |
| | CVE-2026-29076 | Red Hat | medium | 5.9 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-29786 | Red Hat | high | 8.6 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creati… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-29186 | Red Hat | high | 9.1 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a co… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-29184 | Red Hat | low | 2.0 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious s… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-29185 | Red Hat | low | 2.7 | Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerabil… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-24308 | Apache | high | 7.5 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all pla… | Mar 7, 2026 | Mar 10, 2026 |
| | CVE-2026-24281 | Apache | high | 7.4 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN… | Mar 7, 2026 | Mar 10, 2026 |
| | CVE-2026-24308 | Red Hat | medium | 3.3 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all pla… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-24281 | Red Hat | medium | 4.4 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN… | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-30827 | Red Hat | medium | 7.5 | express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 … | Mar 7, 2026 | Mar 7, 2026 |
| | CVE-2026-30242 | Check Point | high | 8.5 | Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validati… | Mar 6, 2026 | Mar 10, 2026 |
| | CVE-2026-27139 | Red Hat | low | 2.5 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the r… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-27138 | Red Hat | low | 3.7 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-27142 | Red Hat | medium | 5.4 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-25679 | Red Hat | medium | 5.3 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-27137 | Red Hat | medium | 5.3 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-30231 | Red Hat | medium | 6.5 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools.… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-30230 | Red Hat | medium | 5.3 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools.… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69651 | Check Point | medium | 5.5 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when p… | Mar 6, 2026 | Mar 10, 2026 |
| | CVE-2026-3419 | Red Hat | medium | 5.3 | Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after th… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-29089 | Red Hat | high | 8.8 | TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgre… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-26017 | Red Hat | high | 7.7 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in Cor… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-26018 | Red Hat | high | 7.5 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerabil… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-23925 | Red Hat | medium | 7.6 | An authenticated Zabbix user (User role) with template/host write permissions is able to create obje… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-29062 | Red Hat | high | 7.5 | jackson-core contains core low-level incremental ("streaming") parser and generator abstractions use… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-28804 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who use… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-28802 | Red Hat | high | 9.1 | Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to bef… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-28799 | Red Hat | high | 7.5 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-29068 | Red Hat | high | 9.8 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-3632 | Red Hat | low | 3.9 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-3633 | Red Hat | low | 3.9 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-3634 | Red Hat | medium | 3.9 | No description is available for this CVE. | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69645 | Red Hat | low | 2.8 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with ma… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69644 | Red Hat | low | 2.8 | An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerabil… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69646 | Red Hat | low | 2.8 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with ma… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69650 | Red Hat | low | 3.3 | GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF bi… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69652 | Red Hat | low | 3.3 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when proces… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69649 | Red Hat | low | 3.3 | GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a c… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2025-69651 | Red Hat | low | 2.8 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when p… | Mar 6, 2026 | Mar 6, 2026 |
| | CVE-2026-21536 | Microsoft | critical | 9.8 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | Mar 5, 2026 | Mar 9, 2026 |
| | CVE-2026-3606 | Red Hat | medium | 4.4 | A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the fun… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-29054 | Red Hat | high | 7.5 | Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version … | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-26999 | Red Hat | high | 7.5 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a … | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-26998 | Red Hat | medium | 4.4 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a … | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-25048 | Red Hat | high | 7.5 | xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prio… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-2092 | Red Hat | high | 7.7 | No description is available for this CVE. | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-3047 | Red Hat | high | 8.8 | A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SA… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-2603 | Red Hat | high | 8.1 | No description is available for this CVE. | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-3009 | Red Hat | high | 8.1 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-1605 | Red Hat | high | 7.5 | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerabili… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2025-11143 | Red Hat | low | 3.7 | The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unu… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-27982 | Red Hat | medium | 4.3 | An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP init… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2025-40931 | Apache | critical | 9.1 | Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id.
Apache::S… | Mar 5, 2026 | Mar 9, 2026 |
| | CVE-2026-3381 | Red Hat | medium | 5.3 | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib.
Compr… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2025-69534 | Red Hat | high | 8.2 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause ht… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2025-45691 | Red Hat | high | 7.5 | An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients… | Mar 5, 2026 | Mar 5, 2026 |
| | CVE-2026-2297 | Red Hat | low | 3.3 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly han… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27898 | Red Hat | medium | 6.5 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27803 | Red Hat | high | 8.3 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27802 | Red Hat | high | 8.1 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27801 | Red Hat | medium | 8.8 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-20064 | Cisco | medium | 6.5 | A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticat… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20025 | Cisco | medium | 6.8 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20024 | Cisco | medium | 6.8 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20023 | Cisco | medium | 6.1 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20022 | Cisco | medium | 6.1 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20021 | Cisco | medium | 4.3 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20020 | Cisco | medium | 6.8 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20016 | Cisco | medium | 6.0 | A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Se… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-0847 | Red Hat | high | 7.5 | A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path trave… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-20149 | Cisco | medium | 6.1 | A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a c… | Mar 4, 2026 | Mar 9, 2026 |
| | CVE-2026-20131 | Cisco | critical | 10.0 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20106 | Cisco | medium | 5.3 | A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20105 | Cisco | high | 7.7 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20103 | Cisco | high | 8.6 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Securit… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20102 | Cisco | medium | 6.1 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20101 | Cisco | high | 8.6 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20100 | Cisco | high | 7.7 | A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20082 | Cisco | high | 8.6 | A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20079 | Cisco | critical | 10.0 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20073 | Cisco | medium | 5.8 | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20070 | Cisco | medium | 6.1 | A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20069 | Cisco | medium | 4.3 | A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Applian… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20068 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20067 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20066 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20065 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20063 | Cisco | medium | 6.0 | A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20062 | Cisco | high | 7.2 | A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in mu… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20058 | Cisco | medium | 5.8 | Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow … | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20057 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20054 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow … | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20053 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow … | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20052 | Cisco | medium | 5.8 | A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure F… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20050 | Cisco | medium | 6.8 | A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secur… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20049 | Cisco | high | 7.7 | A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange versi… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20044 | Cisco | medium | 6.0 | A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software … | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20039 | Cisco | high | 8.6 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Sof… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20018 | Cisco | medium | 5.9 | A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Softw… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20017 | Cisco | medium | 6.0 | A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20015 | Cisco | medium | 5.8 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20014 | Cisco | high | 7.7 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20013 | Cisco | medium | 5.8 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Soft… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20009 | Cisco | medium | 5.3 | A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20008 | Cisco | medium | 6.0 | A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Se… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20007 | Cisco | medium | 5.8 | A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat De… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20006 | Cisco | medium | 5.8 | A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secur… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20003 | Cisco | medium | 4.9 | A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote at… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20002 | Cisco | high | 8.1 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20001 | Cisco | medium | 6.5 | A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote at… | Mar 4, 2026 | Mar 5, 2026 |
| | CVE-2026-20005 | Cisco | medium | 5.8 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-3520 | Red Hat | high | 7.5 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior t… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2025-15558 | Red Hat | high | 7.3 | Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a director… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23237 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: classmate-laptop:… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2025-71238 | HPE | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix bsg_done() c… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2025-12801 | Red Hat | medium | 6.5 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux,… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27446 | Apache | critical | 9.8 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache Activ… | Mar 4, 2026 | Mar 11, 2026 |
| | CVE-2025-66168 | Apache | medium | 5.4 | Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow … | Mar 4, 2026 | Mar 10, 2026 |
| | CVE-2025-66168 | Red Hat | medium | 5.4 | Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow … | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27446 | Red Hat | high | 9.1 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache Activ… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23231 | Red Hat | medium | 7.5 | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix use-af… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23236 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
fbdev: smscufx: properly copy io… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23232 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
Revert "f2fs: block cache/dio wr… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23238 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
romfs: check sb_set_blocksize() … | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23234 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid UAF in f2fs_w… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23235 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix out-of-bounds access i… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23237 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: classmate-laptop: … | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-23233 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid mapping wrong… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2025-71238 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix bsg_done() ca… | Mar 4, 2026 | Mar 4, 2026 |
| | CVE-2026-27622 | Red Hat | high | 7.4 | OpenEXR provides the specification and reference implementation of the EXR file format, an image sto… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-27601 | Red Hat | medium | 5.9 | Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3224 | Microsoft | critical | 9.8 | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server… | Mar 3, 2026 | Mar 5, 2026 |
| | CVE-2026-2376 | Red Hat | medium | 4.9 | No description is available for this CVE. | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3494 | Red Hat | medium | 4.3 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_even… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-0540 | Red Hat | medium | 6.1 | DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2025-15599 | Red Hat | medium | 6.1 | DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability t… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-25674 | Red Hat | low | 3.7 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
Race conditio… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-25673 | Red Hat | high | 7.5 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
`URLField.to_… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3449 | Red Hat | medium | 4.0 | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scop… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-2628 | Microsoft | critical | 9.8 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to a… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3540 | Red Hat | high | 8.8 | Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote a… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3536 | Red Hat | high | 8.8 | Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to pote… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3545 | Red Hat | high | 8.8 | Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3542 | Red Hat | high | 8.8 | Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remot… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3538 | Red Hat | high | 8.8 | Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to poten… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3541 | Red Hat | high | 8.8 | Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attack… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3539 | Red Hat | high | 8.8 | Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who … | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3543 | Red Hat | high | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacke… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3544 | Red Hat | high | 8.8 | Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker… | Mar 3, 2026 | Mar 3, 2026 |
| | CVE-2026-3338 | Red Hat | high | 7.5 | Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass s… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-3337 | Red Hat | medium | 6.5 | Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to pote… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-3336 | Red Hat | high | 7.5 | Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-2256 | Red Hat | medium | 6.5 | A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, al… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-25884 | Red Hat | low | 5.3 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP … | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-27596 | Red Hat | low | 5.3 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP … | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-27631 | Red Hat | low | 5.3 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP … | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-23865 | Red Hat | medium | 5.3 | An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in vers… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-23600 | HPE | medium | — | A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS). | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2025-58107 | Microsoft | high | 7.5 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers … | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-3441 | Red Hat | medium | 6.1 | No description is available for this CVE. | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-3442 | Red Hat | medium | 6.1 | No description is available for this CVE. | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-3429 | Red Hat | medium | 4.2 | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lowe… | Mar 2, 2026 | Mar 2, 2026 |
| | CVE-2026-28422 | Red Hat | low | 2.2 | Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow … | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28421 | Red Hat | medium | 5.3 | Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overf… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28420 | Red Hat | medium | 4.4 | Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer over… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28419 | Red Hat | medium | 5.3 | Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer unde… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28418 | Red Hat | medium | 5.3 | Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer over… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28417 | Red Hat | medium | 4.4 | Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection … | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28416 | Red Hat | high | 8.2 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Se… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28415 | Red Hat | medium | 4.3 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the … | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-27167 | Red Hat | low | 3.7 | Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 a… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28406 | Red Hat | high | 8.5 | kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes clust… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28351 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who use… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-22717 | VMware | low | 2.7 | Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor… | Feb 27, 2026 | Mar 2, 2026 |
| | CVE-2026-22716 | VMware | medium | 5.0 | Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an acto… | Feb 27, 2026 | Mar 2, 2026 |
| | CVE-2026-2293 | Red Hat | high | 7.5 | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-3304 | Red Hat | high | 7.5 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior t… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-2359 | Red Hat | high | 7.5 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior t… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-3293 | Red Hat | low | 3.3 | A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function S… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28364 | Red Hat | high | 7.9 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/… | Feb 27, 2026 | Feb 27, 2026 |
| | CVE-2026-28208 | Red Hat | medium | 5.9 | Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversa… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-22715 | VMware | medium | 5.9 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known att… | Feb 26, 2026 | Feb 27, 2026 |
| | CVE-2026-27141 | Red Hat | medium | 5.3 | Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27970 | Red Hat | high | 7.1 | Angular is a development platform for building mobile and desktop web applications using TypeScript/… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27959 | Red Hat | high | 8.2 | Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa'… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27942 | Red Hat | medium | 7.5 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object wi… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27945 | Check Point | medium | 6.5 | ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early previ… | Feb 26, 2026 | Mar 5, 2026 |
| | CVE-2026-27904 | Red Hat | medium | 6.5 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objec… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27903 | Red Hat | medium | 5.9 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objec… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27902 | Red Hat | medium | 4.2 | Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` wer… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27901 | Red Hat | medium | 5.4 | Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText`… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27896 | Red Hat | high | 7.2 | The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message pars… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27830 | Red Hat | high | 8.0 | c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serial… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27888 | Red Hat | medium | 5.3 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this v… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27837 | Red Hat | medium | 6.3 | Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 co… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27976 | Check Point | high | 8.8 | Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, … | Feb 26, 2026 | Mar 5, 2026 |
| | CVE-2026-3234 | Red Hat | low | 4.3 | No description is available for this CVE. | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-28296 | Red Hat | medium | 4.3 | A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vuln… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-28295 | Red Hat | low | 4.3 | A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by p… | Feb 26, 2026 | Feb 26, 2026 |
| | CVE-2026-27799 | Red Hat | medium | 4.0 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27798 | Red Hat | medium | 7.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27148 | Red Hat | high | 8.8 | Storybook is a frontend workshop for building user interface components and pages in isolation. Prio… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-22721 | VMware | medium | 6.2 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privile… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-27951 | Red Hat | medium | 5.9 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the functi… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27950 | Red Hat | medium | 4.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix fo… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26986 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_wind… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26965 | Red Hat | high | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3172 | Red Hat | medium | 6.8 | Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user … | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26955 | Red Hat | high | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a maliciou… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27015 | Red Hat | medium | 6.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing … | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26271 | Red Hat | medium | 4.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer o… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25997 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipbo… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25959 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprd… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25955 | Red Hat | medium | 4.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpd… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25954 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_s… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25953 | Red Hat | medium | 4.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpd… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25952 | Red Hat | medium | 6.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWin… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-2636 | Microsoft | medium | 5.5 | This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" we… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-22720 | VMware | high | 8.0 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with … | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-22719 | VMware | high | 8.1 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-25942 | Red Hat | medium | 4.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_s… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-25941 | Red Hat | medium | 5.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27795 | Red Hat | medium | 6.5 | LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-b… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-20133 | Cisco | medium | 6.5 | A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to … | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-20129 | Cisco | critical | 9.8 | A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unaut… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-20128 | Cisco | high | 7.5 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could al… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-20127 | Cisco | critical | 10.0 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN v… | Feb 25, 2026 | Feb 26, 2026 |
| | CVE-2026-20126 | Cisco | high | 8.8 | A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with l… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-20122 | Cisco | medium | 5.4 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote att… | Feb 25, 2026 | Mar 4, 2026 |
| | CVE-2026-20107 | Cisco | medium | 5.5 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Control… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20099 | Cisco | medium | 6.7 | A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Mana… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20091 | Cisco | medium | 4.8 | A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager S… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20051 | Cisco | high | 7.4 | A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 P… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20048 | Cisco | high | 7.7 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Serie… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20037 | Cisco | medium | 4.4 | A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authe… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20036 | Cisco | medium | 6.5 | A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could al… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20033 | Cisco | high | 7.4 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticate… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-20010 | Cisco | high | 7.4 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could al… | Feb 25, 2026 | Feb 27, 2026 |
| | CVE-2026-25554 | Red Hat | high | 8.2 | OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain … | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27794 | Red Hat | medium | 6.6 | LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0,… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-22866 | Check Point | high | 7.5 | Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethere… | Feb 25, 2026 | Mar 13, 2026 |
| | CVE-2026-27727 | Red Hat | high | 8.3 | mchange-commons-java, a library that provides Java utilities, includes code that mirrors early imple… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27699 | Red Hat | high | 7.5 | The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in v… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3203 | Red Hat | medium | 5.5 | RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3202 | Red Hat | medium | 5.5 | NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3201 | Red Hat | medium | 5.5 | USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows … | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-21725 | Red Hat | low | 2.6 | A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sou… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2025-11563 | Red Hat | medium | 6.5 | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into
saving the output file out… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3190 | Red Hat | medium | 4.3 | No description is available for this CVE. | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26104 | Red Hat | medium | 5.5 | A flaw was found in the udisks storage management daemon that allows unprivileged users to back up L… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-26103 | Red Hat | high | 7.1 | A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for res… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-3184 | Red Hat | low | 3.7 | No description is available for this CVE. | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27628 | Red Hat | medium | 7.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this v… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27606 | Red Hat | high | 9.1 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollu… | Feb 25, 2026 | Feb 25, 2026 |
| | CVE-2026-27572 | Red Hat | medium | 6.3 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0,… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-27204 | Red Hat | medium | 6.3 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0,… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-27195 | Red Hat | medium | 4.7 | Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` fe… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-27571 | Red Hat | medium | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2807 | Red Hat | high | 7.5 | Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2806 | Red Hat | low | 3.4 | Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148 and T… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2805 | Red Hat | medium | 6.1 | Invalid pointer in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thun… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2804 | Red Hat | medium | 6.1 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 an… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2803 | Red Hat | medium | 6.1 | Information disclosure, mitigation bypass in the Settings UI component. This vulnerability affects F… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2802 | Red Hat | medium | 6.1 | Race condition in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunder… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2801 | Red Hat | medium | 6.1 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects F… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2800 | Red Hat | medium | 6.1 | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2799 | Red Hat | high | 7.5 | Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thund… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2798 | Red Hat | high | 7.5 | Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thund… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2797 | Red Hat | high | 7.5 | Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunder… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2796 | Red Hat | high | 7.5 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 14… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2795 | Red Hat | high | 7.5 | Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunder… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2794 | Red Hat | high | 7.5 | Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vu… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2793 | Red Hat | high | 7.5 | Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2792 | Red Hat | high | 7.5 | Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2791 | Red Hat | low | 3.4 | Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Fire… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2790 | Red Hat | low | 3.4 | Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 148… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2788 | Red Hat | medium | 6.1 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2789 | Red Hat | medium | 6.1 | Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2787 | Red Hat | medium | 6.1 | Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2785 | Red Hat | medium | 6.1 | Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2786 | Red Hat | medium | 6.1 | Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2784 | Red Hat | medium | 6.1 | Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148, Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2783 | Red Hat | medium | 6.1 | Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulne… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2782 | Red Hat | medium | 6.1 | Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2781 | Red Hat | medium | 6.1 | Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2779 | Red Hat | medium | 6.1 | Incorrect boundary conditions in the Networking: JAR component. This vulnerability affects Firefox <… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2780 | Red Hat | medium | 6.1 | Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2778 | Red Hat | high | 7.5 | Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerab… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2776 | Red Hat | high | 7.5 | Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2777 | Red Hat | high | 7.5 | Privilege escalation in the Messaging System component. This vulnerability affects Firefox < 148, Fi… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2775 | Red Hat | high | 7.5 | Mitigation bypass in the DOM: HTML Parser component. This vulnerability affects Firefox < 148, Firef… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2774 | Red Hat | high | 7.5 | Integer overflow in the Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2773 | Red Hat | high | 7.5 | Incorrect boundary conditions in the Web Audio component. This vulnerability affects Firefox < 148, … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2772 | Red Hat | high | 7.5 | Use-after-free in the Audio/Video: Playback component. This vulnerability affects Firefox < 148, Fir… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2771 | Red Hat | high | 7.5 | Undefined behavior in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Fire… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2770 | Red Hat | high | 7.5 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability affects Firefox < 148, Fi… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2769 | Red Hat | high | 7.5 | Use-after-free in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2768 | Red Hat | high | 7.5 | Sandbox escape in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2767 | Red Hat | high | 7.5 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148, F… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2766 | Red Hat | high | 7.5 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Fi… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2764 | Red Hat | high | 7.5 | JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability affec… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2765 | Red Hat | high | 7.5 | Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2763 | Red Hat | high | 7.5 | Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2762 | Red Hat | high | 7.5 | Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox <… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2761 | Red Hat | high | 7.5 | Sandbox escape in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firef… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2760 | Red Hat | high | 7.5 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulne… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2759 | Red Hat | high | 7.5 | Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefo… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2758 | Red Hat | high | 7.5 | Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ES… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-2757 | Red Hat | high | 7.1 | Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability affects Firef… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-3121 | Red Hat | medium | 6.5 | No description is available for this CVE. | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26981 | Red Hat | medium | 6.5 | OpenEXR provides the specification and reference implementation of the EXR file format, an image sto… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26331 | Red Hat | high | 8.8 | yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26983 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26284 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26283 | Red Hat | medium | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-26066 | Red Hat | medium | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25989 | Red Hat | medium | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25988 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25987 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25986 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25985 | Red Hat | high | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25983 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25982 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25971 | Red Hat | medium | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25970 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25969 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25968 | Red Hat | medium | 7.4 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25967 | Red Hat | medium | 7.4 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25966 | Red Hat | medium | 5.9 | ImageMagick is free and open-source software used for editing and manipulating digital images. The s… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25965 | Red Hat | high | 8.6 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25898 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25897 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25799 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25798 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25797 | Red Hat | medium | 5.7 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-3099 | Red Hat | medium | 5.8 | No description is available for this CVE. | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25796 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25795 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25794 | Red Hat | high | 8.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. `Writ… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25638 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25637 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-25576 | Red Hat | medium | 5.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-24485 | Red Hat | medium | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-24484 | Red Hat | medium | 5.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-3118 | Red Hat | medium | 6.5 | A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The … | Feb 24, 2026 | Feb 24, 2026 |
| | CVE-2026-27623 | Red Hat | high | 7.5 | Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a … | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-21863 | Red Hat | high | 7.5 | Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a mal… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2025-67733 | Red Hat | high | 7.1 | Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a mal… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-25747 | Red Hat | high | 7.8 | Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component.
The Camel-LevelDB… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2025-14905 | Red Hat | medium | 7.2 | A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `sche… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2025-61145 | Red Hat | medium | 5.0 | libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2025-61144 | Red Hat | medium | 5.0 | libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2025-61143 | Red Hat | medium | 5.5 | libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-3062 | Red Hat | high | 8.8 | Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remot… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-3061 | Red Hat | high | 8.8 | Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to pe… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-3063 | Red Hat | high | 8.8 | Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacke… | Feb 23, 2026 | Feb 23, 2026 |
| | CVE-2026-2913 | Red Hat | low | 2.5 | A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_so… | Feb 22, 2026 | Feb 22, 2026 |
| | CVE-2026-2903 | Check Point | low | 3.3 | A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_r… | Feb 22, 2026 | Feb 23, 2026 |
| | CVE-2026-2903 | Red Hat | low | 3.3 | A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_r… | Feb 22, 2026 | Feb 22, 2026 |
| | CVE-2026-27205 | Red Hat | medium | 4.3 | Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and belo… | Feb 21, 2026 | Feb 21, 2026 |
| | CVE-2026-27134 | Red Hat | high | 8.1 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27133 | Red Hat | medium | 5.9 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27125 | Red Hat | medium | 5.6 | svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spre… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27122 | Red Hat | medium | 5.6 | svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> i… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27121 | Red Hat | medium | 5.6 | svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cros… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27119 | Red Hat | medium | 5.6 | svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the serv… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2048 | Red Hat | high | 7.8 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2047 | Red Hat | high | 7.8 | GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2045 | Red Hat | high | 7.3 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2044 | Red Hat | high | 8.8 | GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability a… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2492 | Red Hat | high | 7.8 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. T… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-0797 | Red Hat | high | 8.8 | GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27026 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this v… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27025 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this v… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-27024 | Red Hat | medium | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this v… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-25896 | Red Hat | high | 7.1 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object wi… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2472 | Red Hat | high | 8.1 | Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Verte… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2818 | Red Hat | high | 7.1 | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows … | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-21620 | Red Hat | medium | 4.2 | Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erla… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-2739 | Red Hat | medium | 5.3 | This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupt… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-26996 | Red Hat | medium | 6.5 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objec… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-26960 | Red Hat | medium | 7.1 | node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below,… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-26967 | Red Hat | high | 8.4 | PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and … | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-3196 | Red Hat | medium | 5.5 | An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the … | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-3195 | Red Hat | high | 7.4 | A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `vir… | Feb 20, 2026 | Feb 20, 2026 |
| | CVE-2026-26963 | Red Hat | medium | 6.1 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions … | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-21535 | Microsoft | high | 8.2 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information o… | Feb 19, 2026 | Feb 20, 2026 |
| | CVE-2026-26958 | Red Hat | low | 3.7 | filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for b… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-24122 | Red Hat | low | 3.7 | Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and bel… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-26267 | Check Point | high | 7.5 | soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the … | Feb 19, 2026 | Feb 20, 2026 |
| | CVE-2026-26318 | Red Hat | high | 8.8 | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are v… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-26280 | Red Hat | high | 8.4 | systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-26278 | Red Hat | high | 7.5 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object wi… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-26200 | Red Hat | high | 7.8 | HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` f… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-26030 | Microsoft | critical | 9.9 | Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability i… | Feb 19, 2026 | Mar 3, 2026 |
| | CVE-2026-2817 | Red Hat | medium | 4.4 | Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, p… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-24834 | Red Hat | high | 9.3 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtu… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-25940 | Red Hat | high | 9.6 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and me… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-25755 | Red Hat | high | 9.6 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of t… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-25535 | Red Hat | high | 7.5 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argumen… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2026-2733 | Red Hat | low | 3.8 | A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2025-69725 | Red Hat | medium | 4.7 | An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote atta… | Feb 19, 2026 | Feb 19, 2026 |
| | CVE-2025-10256 | Check Point | medium | 5.3 | A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_fire… | Feb 18, 2026 | Feb 26, 2026 |
| | CVE-2026-2708 | Red Hat | low | 3.7 | No description is available for this CVE. | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-25500 | Red Hat | medium | 5.4 | Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Dir… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-22860 | Red Hat | high | 7.5 | Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Dir… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-20144 | Splunk | medium | 6.8 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platf… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2026-20142 | Splunk | medium | 6.8 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Sea… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2026-20141 | Splunk | medium | 4.3 | In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2026-20139 | Splunk | medium | 4.3 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platf… | Feb 18, 2026 | Feb 20, 2026 |
| | CVE-2026-20138 | Splunk | medium | 6.8 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Sea… | Feb 18, 2026 | Feb 20, 2026 |
| | CVE-2026-20137 | Splunk | low | 3.5 | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platfo… | Feb 18, 2026 | Feb 20, 2026 |
| | CVE-2025-14009 | Red Hat | high | 8.8 | A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all version… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2507 | F5 | high | 7.5 | When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23220 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix infinite loop caused… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2025-71236 | HPE | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Validate sp befo… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2025-71236 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Validate sp befo… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2025-71232 | HPE | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Free sp in error… | Feb 18, 2026 | Feb 23, 2026 |
| | CVE-2026-23215 | VMware | medium | — | In the Linux kernel, the following vulnerability has been resolved:
x86/vmware: Fix hypercall clobb… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-27100 | Red Hat | medium | 4.3 | Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-27099 | Red Hat | medium | 4.6 | Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2641 | Red Hat | low | 3.3 | A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the fun… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-27171 | Red Hat | low | 2.9 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23599 | HPE | high | 7.8 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-22048 | Microsoft | high | 7.1 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sig… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2681 | Red Hat | medium | 5.3 | A flaw was found in the blst cryptographic library. This out-of-bounds stack write vulnerability, sp… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23211 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mm, swap: restore swap_space att… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71228 | Red Hat | medium | — | No description is available for this CVE. | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23218 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gpio: loongson-64bit: Fix incorr… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23219 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mm/slab: Add alloc_tagging_slab_… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23215 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
x86/vmware: Fix hypercall clobbe… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71225 | Red Hat | medium | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
md: suspend array while updating… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23216 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix use-aft… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23214 | Red Hat | medium | 5.1 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject new transactions i… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23212 | Red Hat | medium | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
bonding: annotate data-races aro… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23217 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
riscv: trace: fix snapshot deadl… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71227 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: don't WARN for c… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23213 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amd/pm: Disable MMIO access … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71226 | Red Hat | medium | 0.0 | A compatibility issue was found in the Linux kernel's iwlwifi driver. The PTP clock registration for… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71230 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
hfs: ensure sb->s_fs_info is alw… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71235 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Delay module unlo… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23228 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
smb: server: fix leak of active_… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23230 | Red Hat | medium | 6.3 | In the Linux kernel, the following vulnerability has been resolved:
smb: client: split cached_fid bi… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23220 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix infinite loop caused … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71231 | Red Hat | medium | 6.6 | In the Linux kernel, the following vulnerability has been resolved:
crypto: iaa - Fix out-of-bounds … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23224 | Red Hat | medium | 6.6 | In the Linux kernel, the following vulnerability has been resolved:
erofs: fix UAF issue for file-ba… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23221 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
bus: fsl-mc: fix use-after-free … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71236 | Red Hat | medium | 5.8 | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Validate sp befor… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23229 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
crypto: virtio - Add spinlock pr… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23222 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
crypto: omap - Allocate OMAP_CRY… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71229 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw88: Fix alignment fault… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71233 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
PCI: endpoint: Avoid creating su… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71232 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Free sp in error … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71234 | Red Hat | medium | 5.8 | In the Linux kernel, the following vulnerability has been resolved:
wifi: rtl8xxxu: fix slab-out-of-… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2025-71237 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
nilfs2: Fix potential block over… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23227 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/exynos: vidi: use ctx->lock … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23223 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
xfs: fix UAF in xchk_btree_check… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23226 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23225 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
sched/mmcid: Don't assume CID is… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2648 | Red Hat | high | 8.8 | Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2649 | Red Hat | high | 8.8 | Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potenti… | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-2650 | Red Hat | medium | 6.5 | Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to … | Feb 18, 2026 | Feb 18, 2026 |
| | CVE-2026-23598 | HPE | medium | 6.5 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow… | Feb 17, 2026 | Feb 28, 2026 |
| | CVE-2026-23597 | HPE | medium | 6.5 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow… | Feb 17, 2026 | Mar 2, 2026 |
| | CVE-2026-24734 | Apache | high | 7.5 | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP … | Feb 17, 2026 | Mar 11, 2026 |
| | CVE-2026-24733 | Apache | low | 3.7 | Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests t… | Feb 17, 2026 | Mar 11, 2026 |
| | CVE-2025-66614 | Apache | critical | 9.1 | Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 1… | Feb 17, 2026 | Mar 11, 2026 |
| | CVE-2026-24734 | Red Hat | high | 7.4 | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP r… | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2026-24733 | Red Hat | low | 5.3 | Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to … | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2025-66614 | Red Hat | medium | 5.3 | Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11… | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2026-24708 | Red Hat | high | 7.1 | An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By … | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2026-25087 | Check Point | high | 7.0 | Use After Free vulnerability in Apache Arrow C++.
This issue affects Apache Arrow C++ from 15.0.0 t… | Feb 17, 2026 | Mar 11, 2026 |
| | CVE-2026-25087 | Apache | high | 7.0 | Use After Free vulnerability in Apache Arrow C++.
This issue affects Apache Arrow C++ from 15.0.0 t… | Feb 17, 2026 | Mar 11, 2026 |
| | CVE-2026-25087 | Red Hat | medium | 5.3 | Use After Free vulnerability in Apache Arrow C++.
This issue affects Apache Arrow C++ from 15.0.0 th… | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2026-2625 | Red Hat | medium | 4.0 | No description is available for this CVE. | Feb 17, 2026 | Feb 17, 2026 |
| | CVE-2026-2447 | Red Hat | high | 7.5 | Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1,… | Feb 16, 2026 | Feb 16, 2026 |
| | CVE-2026-2604 | Red Hat | medium | 5.6 | No description is available for this CVE. | Feb 16, 2026 | Feb 16, 2026 |
| | CVE-2026-2575 | Red Hat | medium | 5.3 | No description is available for this CVE. | Feb 16, 2026 | Feb 16, 2026 |
| | CVE-2026-2574 | Red Hat | low | 5.4 | A flaw was found in glib-networking. A malicious Transport Layer Security (TLS) server can exploit a… | Feb 16, 2026 | Feb 16, 2026 |
| | CVE-2026-23207 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
spi: tegra210-quad: Protect cur… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23206 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: prevent ZERO_SIZE… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23202 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
spi: tegra210-quad: Protect cur… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23201 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid p… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23198 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't clobber irqfd routin… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23196 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: … | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23191 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ALSA: aloop: Fix racy access at… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23189 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ceph: fix NULL pointer derefere… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23186 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
hwmon: (acpi_power_meter) Fix d… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23183 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
cgroup/dmem: fix NULL pointer d… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23177 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mm, shmem: prevent infinite loo… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23166 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ice: Fix NULL pointer dereferen… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23163 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix NULL pointer de… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23159 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
perf: sched: Fix perf crash wit… | Feb 14, 2026 | Feb 18, 2026 |
| | CVE-2026-23114 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
arm64/fpsimd: ptrace: Fix SVE wr… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23145 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
ext4: fix iloc.bh leak in ext4_x… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23124 | Red Hat | medium | 5.9 | In the Linux kernel, the following vulnerability has been resolved:
ipv6: annotate data-race in ndis… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23137 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
of: unittest: Fix memory leak in… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23123 | Red Hat | low | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
interconnect: debugfs: initializ… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23133 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
wifi: ath10k: fix dma_free_coher… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23135 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix dma_free_coher… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23121 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mISDN: annotate data-race around… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23127 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
perf: Fix refcount warning on ev… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23120 | Red Hat | medium | 5.8 | In the Linux kernel, the following vulnerability has been resolved:
l2tp: avoid one data-race in l2t… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23143 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
virtio_net: Fix misalignment bug… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23136 | Red Hat | medium | 7.6 | In the Linux kernel, the following vulnerability has been resolved:
libceph: reset sparse-read state… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23116 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
pmdomain: imx8m-blk-ctrl: Remove… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23140 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
bpf, test_run: Subtract size of … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23131 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: hp-bioscfg: Fix ko… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71200 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mmc: sdhci-of-dwcmshc: Prevent i… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23122 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
igc: Reduce TSN TX packet buffer… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23125 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
sctp: move SCTP_CMD_ASSOC_SHKEY … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71202 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
iommu/sva: invalidate stale IOTL… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23118 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix data-race warning and… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71201 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix early read unlock of … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23134 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
slab: fix kmalloc_nolock() conte… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23141 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: send: check for inline ex… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23126 | Red Hat | medium | 6.3 | In the Linux kernel, the following vulnerability has been resolved:
netdevsim: fix a race issue rela… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23128 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
arm64: Set __nocfi on swsusp_arc… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23132 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: synopsys: dw-dp: fix… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23113 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
io_uring/io-wq: check IO_WQ_BIT_… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23138 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
tracing: Add recursion protectio… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23142 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-scheme: cleanup a… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23130 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix dead lock whil… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23115 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
serial: Fix not set tty->port ra… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23144 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs: cleanup attrs su… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23119 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
bonding: provide a net pointer t… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23139 | Red Hat | medium | 7.6 | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conncount: update … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23117 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ice: add missing ice_deinit_hw()… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23129 | Red Hat | medium | 5.6 | In the Linux kernel, the following vulnerability has been resolved:
dpll: Prevent duplicate registra… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23176 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: toshiba_haps: Fix … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23146 | Red Hat | medium | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: fix null-pt… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23152 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: correctly decode… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23180 | Red Hat | medium | 5.0 | In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: add bounds check f… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23169 | Red Hat | medium | 5.6 | In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix race in mptcp_pm_nl_f… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23171 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
bonding: fix use-after-free due … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23193 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix use-aft… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23189 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ceph: fix NULL pointer dereferen… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71222 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
wifi: wlcore: ensure skb headroo… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23183 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
cgroup/dmem: fix NULL pointer de… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23166 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
ice: Fix NULL pointer dereferenc… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23164 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
rocker: fix memory leak in rocke… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23150 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: Fix memleak in nfc_ll… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23188 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
net: usb: r8152: fix resume rese… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23210 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
ice: Fix PTP NULL pointer derefe… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23197 | Red Hat | medium | 6.3 | In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: preserve error state i… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23207 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
spi: tegra210-quad: Protect curr… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23155 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23160 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
octeon_ep: Fix memory leak in oc… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23209 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
macvlan: fix error recovery in m… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23194 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
rust_binder: correctly handle FD… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23200 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix ECMP sibling count mis… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23157 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: do not strictly require d… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23148 | Red Hat | medium | 5.7 | In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix race in nvmet_bio_don… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23203 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: cpsw_new: Execute ndo_set_r… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23208 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Prevent excessi… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23196 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
HID: Intel-thc-hid: Intel-thc: A… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23202 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
spi: tegra210-quad: Protect curr… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71221 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: mmp_pdma: Fix race co… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23158 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gpio: virtuser: fix UAF in confi… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23198 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't clobber irqfd routing… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23170 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/imx/tve: fix probe device le… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23205 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
smb/client: fix memory leak in s… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23178 | Red Hat | medium | 6.4 | In the Linux kernel, the following vulnerability has been resolved:
HID: i2c-hid: fix potential buff… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23174 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
nvme-pci: handle changing device… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71223 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
smb/server: fix refcount leak in… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23190 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
ASoC: amd: fix memory leak in ac… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23192 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
linkwatch: use __dev_put() in ca… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23199 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
procfs: avoid fetching build ID … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23184 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder_netlin… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23161 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mm/shmem, swap: fix race of trun… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23165 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
sfc: fix deadlock in RSS config … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23195 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
cgroup/dmem: avoid pool UAF
An U… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23172 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: wwan: t7xx: fix potential s… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23185 | Red Hat | high | 6.7 | In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_s… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23151 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: Fix memory leak… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71204 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
smb/server: fix refcount leak in… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71224 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: ocb: skip rx_no_… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23177 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mm, shmem: prevent infinite loop… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71203 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
riscv: Sanitize syscall table in… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23204 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_u32: use skb_head… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23187 | Red Hat | medium | 6.0 | In the Linux kernel, the following vulnerability has been resolved:
pmdomain: imx8m-blk-ctrl: fix ou… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23154 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
net: fix segmentation of forward… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23181 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: sync read disk super and … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23159 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
perf: sched: Fix perf crash with… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23162 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/xe/nvm: Fix double-free on a… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23163 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix NULL pointer der… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23182 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
spi: tegra: Fix a memory leak in… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23201 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid po… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23147 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: zlib: fix the folio leak … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23168 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
flex_proportions: make fprop_new… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23173 | Red Hat | medium | 4.1 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: TC, delete flows only… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23206 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: prevent ZERO_SIZE_… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23167 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: Fix race between rfkil… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23149 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
drm: Do not allow userspace to t… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23175 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: cpsw: Execute ndo_set_rx_mo… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23191 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: aloop: Fix racy access at … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23153 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
firewire: core: fix race conditi… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23186 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
hwmon: (acpi_power_meter) Fix de… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71220 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
smb/server: call ksmbd_session_r… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23156 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
efivarfs: fix error propagation … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23179 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fixup hang in nvmet_t… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-26269 | Red Hat | low | 7.5 | Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerab… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2025-33042 | Red Hat | medium | 5.6 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-2443 | Red Hat | low | 5.3 | A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-23112 | Red Hat | medium | 7.6 | In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: add bounds checks in … | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-23111 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix invert… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-2441 | Red Hat | high | 8.8 | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute a… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-25949 | Red Hat | high | 7.5 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerabili… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2007 | Red Hat | high | 8.2 | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a c… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2006 | Red Hat | high | 8.8 | Missing validation of multibyte character length in PostgreSQL text manipulation allows a database u… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2005 | Red Hat | high | 8.8 | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code a… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2004 | Red Hat | high | 8.8 | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function … | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2003 | Red Hat | medium | 4.3 | Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2025-41117 | Red Hat | medium | 6.8 | Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-21722 | Red Hat | medium | 5.3 | Public dashboards with annotations enabled did not limit their annotation timerange to the locked ti… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2327 | Red Hat | medium | 7.5 | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expressi… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2391 | Red Hat | medium | 5.3 | ### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `c… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-1669 | Red Hat | high | 6.5 | Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 throug… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26012 | Red Hat | medium | 6.5 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26019 | Red Hat | medium | 4.1 | LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoa… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26014 | Red Hat | medium | 5.9 | Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 thr… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-25990 | Red Hat | high | 7.3 | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be trigg… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2020-37178 | Red Hat | high | 7.5 | KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help sys… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-12474 | Red Hat | low | 3.1 | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but alloc… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-1837 | Red Hat | high | 8.8 | A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2366 | Red Hat | low | 3.1 | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2369 | Red Hat | medium | 6.5 | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26079 | Red Hat | medium | 4.7 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection,… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26157 | Red Hat | high | 7.0 | A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26158 | Red Hat | high | 7.0 | A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the in… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-69872 | Red Hat | high | 7.6 | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attac… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-69873 | Red Hat | high | 7.5 | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Serv… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2436 | Red Hat | medium | 6.5 | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26013 | Red Hat | low | 3.7 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the Chat… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-26007 | Red Hat | high | 7.4 | cryptography is a package designed to expose cryptographic primitives and recipes to Python develope… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-25506 | Red Hat | high | 7.7 | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17,… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2025-14821 | Red Hat | low | 7.8 | A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security down… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0965 | Red Hat | low | 3.3 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0966 | Red Hat | medium | 6.5 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0967 | Red Hat | low | 2.2 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0968 | Red Hat | low | 3.1 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0964 | Red Hat | medium | 5.0 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-21537 | Microsoft | high | 8.8 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an … | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21527 | Microsoft | medium | 6.5 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21514 | Microsoft | high | 7.8 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized … | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21511 | Microsoft | high | 7.5 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to per… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21261 | Microsoft | medium | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21260 | Microsoft | high | 7.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an una… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21259 | Microsoft | high | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate priv… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21258 | Microsoft | medium | 5.5 | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21246 | Microsoft | high | 7.8 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate … | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-21235 | Microsoft | high | 7.3 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l… | Feb 10, 2026 | Feb 11, 2026 |
| | CVE-2026-25646 | Red Hat | high | 7.0 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portabl… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2025-35998 | Red Hat | high | 7.9 | Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technolog… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2025-31648 | Red Hat | low | 2.5 | Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an es… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-22153 | Fortinet | high | 8.1 | An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet Forti… | Feb 10, 2026 | Feb 12, 2026 |
| | CVE-2026-21743 | Fortinet | high | 7.2 | A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthe… | Feb 10, 2026 | Feb 12, 2026 |
| | CVE-2025-68686 | Fortinet | medium | 5.9 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability … | Feb 10, 2026 | Feb 12, 2026 |
| | CVE-2025-64157 | Fortinet | medium | 6.7 | A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, … | Feb 10, 2026 | Feb 12, 2026 |
| | CVE-2025-62676 | Fortinet | high | 7.1 | An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerabili… | Feb 10, 2026 | Feb 12, 2026 |
| | CVE-2025-62439 | Fortinet | medium | 4.2 | An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability … | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2025-55018 | Fortinet | medium | 5.8 | An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet… | Feb 10, 2026 | Feb 23, 2026 |
| | CVE-2025-52436 | Fortinet | high | 8.8 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit… | Feb 10, 2026 | Feb 18, 2026 |
| | CVE-2026-23901 | Red Hat | low | 2.9 | Observable Timing Discrepancy vulnerability in Apache Shiro.
This issue affects Apache Shiro: from 1… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2272 | Red Hat | medium | 4.3 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2271 | Red Hat | medium | 3.3 | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2319 | Red Hat | medium | 6.5 | Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a u… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2320 | Red Hat | medium | 6.5 | Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote … | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2322 | Red Hat | low | 4.3 | Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote … | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2318 | Red Hat | medium | 6.5 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a r… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2323 | Red Hat | low | 4.3 | Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote a… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2313 | Red Hat | high | 8.8 | Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potential… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2315 | Red Hat | high | 8.8 | Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote atta… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2316 | Red Hat | medium | 6.5 | Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote a… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2317 | Red Hat | medium | 6.5 | Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote a… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2321 | Red Hat | medium | 6.5 | Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convin… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2314 | Red Hat | high | 8.8 | Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to … | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2243 | Red Hat | low | 5.1 | A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnera… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-25934 | Red Hat | medium | 4.3 | go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vuln… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-25765 | Red Hat | medium | 5.8 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapt… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-25639 | Red Hat | high | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-1609 | Red Hat | high | 8.1 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is e… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-25598 | Red Hat | medium | 4.3 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to … | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2025-14778 | Red Hat | medium | 5.4 | A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserMa… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24684 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async p… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-1486 | Red Hat | high | 8.8 | A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the s… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24683 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches chan… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24682 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-1529 | Red Hat | high | 8.1 | A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organizati… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24681 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24680 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New fr… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24679 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client … | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24678 | Red Hat | high | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread s… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24677 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compr… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24676 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format reneg… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24675 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interfa… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24491 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can se… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-23948 | Red Hat | medium | 5.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer der… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2025-66630 | Red Hat | high | 7.7 | Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2025-14831 | Red Hat | medium | 5.3 | A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Ce… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-24098 | Apache | medium | 6.5 | Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with per… | Feb 9, 2026 | Mar 11, 2026 |
| | CVE-2026-23903 | Red Hat | medium | 5.3 | Authentication Bypass by Alternate Name vulnerability in Apache Shiro.
This issue affects Apache Shi… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-2239 | Red Hat | low | 2.8 | No description is available for this CVE. | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-1615 | Red Hat | high | 9.8 | Versions of the package jsonpath before 1.2.0 are vulnerable to Arbitrary Code Injection via unsafe … | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-1584 | Red Hat | high | 7.5 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sen… | Feb 9, 2026 | Feb 9, 2026 |
| | CVE-2026-25793 | Red Hat | high | 8.1 | Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 cert… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25749 | Red Hat | medium | 7.3 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow v… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25592 | Microsoft | critical | 9.9 | Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. … | Feb 6, 2026 | Feb 19, 2026 |
| | CVE-2026-25580 | Red Hat | high | 8.6 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. … | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25731 | Red Hat | high | 7.8 | calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability … | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25635 | Red Hat | high | 8.6 | calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnera… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25636 | Red Hat | high | 8.2 | calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25640 | Red Hat | high | 7.1 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. … | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25727 | Red Hat | medium | 5.9 | time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input … | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-24851 | Red Hat | medium | 6.0 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and … | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-1709 | Red Hat | critical | 9.4 | A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-si… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-23740 | Red Hat | high | 7.8 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cer… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-23739 | Red Hat | low | 2.0 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cer… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-25556 | Red Hat | medium | 5.3 | MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_disp… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-21643 | Fortinet | critical | 9.8 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit… | Feb 6, 2026 | Feb 17, 2026 |
| | CVE-2026-2100 | Red Hat | medium | 5.3 | No description is available for this CVE. | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-0598 | Red Hat | medium | 4.2 | A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI c… | Feb 6, 2026 | Feb 6, 2026 |
| | CVE-2026-0391 | Microsoft | medium | 6.5 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows a… | Feb 5, 2026 | Feb 18, 2026 |
| | CVE-2025-68157 | Red Hat | low | 3.7 | Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is en… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2025-68458 | Red Hat | low | 3.7 | Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is en… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2026-25815 | Fortinet | low | 3.2 | Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configu… | Feb 5, 2026 | Feb 6, 2026 |
| | CVE-2025-47911 | Red Hat | medium | 5.3 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing ce… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2025-58190 | Red Hat | medium | 4.3 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certai… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2025-68121 | Red Hat | medium | 7.4 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs field… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2020-37127 | Red Hat | medium | 5.5 | Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allow… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2026-1966 | Red Hat | low | 6.5 | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web U… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2025-61732 | Red Hat | high | 7.4 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resu… | Feb 5, 2026 | Feb 5, 2026 |
| | CVE-2025-22873 | Red Hat | medium | 5.3 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25547 | Red Hat | medium | 6.5 | @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25537 | Red Hat | medium | 7.5 | jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25536 | Red Hat | high | 7.1 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Fr… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25521 | Red Hat | critical | 9.3 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In ver… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25518 | Red Hat | medium | 5.9 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-0948 | Microsoft | medium | 6.5 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID … | Feb 4, 2026 | Feb 11, 2026 |
| | CVE-2025-68699 | Check Point | medium | 6.5 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has … | Feb 4, 2026 | Feb 20, 2026 |
| | CVE-2026-23098 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
netrom: fix double-free in nr_r… | Feb 4, 2026 | Feb 6, 2026 |
| | CVE-2026-23074 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net/sched: Enforce that teql ca… | Feb 4, 2026 | Feb 6, 2026 |
| | CVE-2026-23063 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
uacce: ensure safe queue releas… | Feb 4, 2026 | Feb 6, 2026 |
| | CVE-2026-23062 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: hp-bioscfg: Fix k… | Feb 4, 2026 | Feb 5, 2026 |
| | CVE-2026-23060 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
crypto: authencesn - reject too… | Feb 4, 2026 | Feb 6, 2026 |
| | CVE-2026-20123 | Cisco | medium | 4.3 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager … | Feb 4, 2026 | Mar 10, 2026 |
| | CVE-2026-20119 | Cisco | high | 7.5 | A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) So… | Feb 4, 2026 | Feb 5, 2026 |
| | CVE-2026-20111 | Cisco | medium | 4.8 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a… | Feb 4, 2026 | Mar 10, 2026 |
| | CVE-2026-20098 | Cisco | high | 8.8 | A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an aut… | Feb 4, 2026 | Mar 10, 2026 |
| | CVE-2026-20056 | Cisco | medium | 4.0 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS … | Feb 4, 2026 | Feb 5, 2026 |
| | CVE-2026-23044 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
PM: hibernate: Fix crash when f… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23043 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix NULL pointer derefer… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23042 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix aux device unplugging… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-22549 | F5 | medium | 4.9 | A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions … | Feb 4, 2026 | Feb 13, 2026 |
| | CVE-2026-22548 | F5 | medium | 5.9 | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed req… | Feb 4, 2026 | Feb 13, 2026 |
| | CVE-2026-20732 | F5 | low | 3.1 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacke… | Feb 4, 2026 | Feb 13, 2026 |
| | CVE-2026-20730 | F5 | low | 3.3 | A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attac… | Feb 4, 2026 | Feb 13, 2026 |
| | CVE-2026-1642 | Red Hat | medium | 5.9 | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport La… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-1622 | Red Hat | medium | 5.5 | Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23065 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86/amd: Fix memory lea… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23099 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
bonding: limit BOND_MODE_8023AD … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23082 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23110 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Wake up the error ha… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23061 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
can: kvaser_usb: kvaser_usb_read… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23056 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
uacce: implement mremap in uacce… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71199 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iio: adc: at91-sama5d2_adc: Fix … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23057 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: Coalesce only line… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23042 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix aux device unplugging … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71193 | Red Hat | medium | 5.1 | In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qusb2: Fix NULL pointe… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23052 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not over-allocate ftr… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23070 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
Octeontx2-af: Add proper checks … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23079 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gpio: cdev: Fix resource leaks o… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23101 | Red Hat | low | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
leds: led-class: Only Add LED to… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23068 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
spi: spi-sprd-adi: Fix double fr… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23069 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix potential unde… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23043 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix NULL pointer derefere… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71195 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: xilinx: xdma: Fix reg… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23103 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
ipvlan: Make the addrs_lock be p… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71192 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ALSA: ac97: fix a double free in… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23089 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix use-after-f… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23080 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
can: mcba_usb: mcba_usb_read_bul… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23093 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbd: fix dma_unmap_sg() … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23048 | Red Hat | low | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
udp: call skb_orphan() before sk… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23059 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Sanitize payload … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23053 | Red Hat | medium | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a deadlock involving nf… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23060 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
crypto: authencesn - reject too-… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23063 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
uacce: ensure safe queue release… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23051 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix drm panic null p… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23109 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
fs/writeback: skip AS_NO_DATA_IN… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23073 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
wifi: rsi: Fix memory corruption… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23106 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
timekeeping: Adjust the leap sta… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23100 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix hugetlb_pmd_shar… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23091 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
intel_th: fix device leak on out… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71198 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iio: imu: st_lsm6dsx: fix iio_ch… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23058 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
can: ems_usb: ems_usb_read_bulk_… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23105 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: qfq: Use cl_is_active… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23074 | Red Hat | high | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: Enforce that teql can… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23095 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gue: Fix skb memleak with inner … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71197 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
w1: therm: Fix off-by-one buffer… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23041 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix NULL pointer crash … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23077 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mm/vma: fix anon_vma UAF on mrem… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23102 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
arm64/fpsimd: signal: Fix restor… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23096 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
uacce: fix cdev handling in the … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23064 | Red Hat | low | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_ife: avoid possib… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23086 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: cap TX credit to l… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23044 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
PM: hibernate: Fix crash when fr… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71196 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
phy: stm32-usphyc: Fix off by on… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23097 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
migrate: correct lock ordering f… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23075 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
can: esd_usb: esd_usb_read_bulk_… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23107 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
arm64/fpsimd: signal: Allocate S… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23066 | Red Hat | medium | 7.4 | In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix recvmsg() uncondition… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23040 | Red Hat | medium | 7.6 | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo i… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2025-71194 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix deadlock in wait_curr… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23092 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iio: dac: ad3552r-hs: fix out-of… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23098 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
netrom: fix double-free in nr_ro… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23046 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
virtio_net: fix device mismatch … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23050 | Red Hat | medium | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix a deadlock when return… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23072 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
l2tp: Fix memleak in l2tp_udp_en… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23047 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
libceph: make calc_target() set … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23084 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
be2net: Fix NULL pointer derefer… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23067 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
iommu/io-pgtable-arm: fix size_t… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23054 | Red Hat | low | 7.0 | In the Linux kernel, the following vulnerability has been resolved:
net: hv_netvsc: reject RSS hash … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23094 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
uacce: fix isolate sysfs check c… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23083 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
fou: Don't allow 0 for FOU_ATTR_… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23071 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
regmap: Fix race condition in hw… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23049 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/panel-simple: fix connector … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23078 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: scarlett2: Fix buffer over… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23076 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Fix potential OOB a… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23045 | Red Hat | medium | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
net/ena: fix missing lock when u… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23085 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
irqchip/gic-v3-its: Avoid trunca… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23062 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: hp-bioscfg: Fix ke… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23108 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
can: usb_8dev: usb_8dev_read_bul… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23088 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix crash on synthetic … | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23081 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: phy: intel-xway: fix OF nod… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23090 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
slimbus: core: fix device refere… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23104 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ice: fix devlink reload call tra… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23055 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
i2c: riic: Move suspend handling… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-23087 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: xen: scsiback: Fix potenti… | Feb 4, 2026 | Feb 4, 2026 |
| | CVE-2026-25223 | Red Hat | high | 7.5 | Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation … | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-25224 | Red Hat | low | 3.7 | Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-s… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-14550 | Red Hat | medium | 7.5 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`ASGIRequest`… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-1312 | Red Hat | high | 8.5 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`.QuerySet.or… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-1287 | Red Hat | high | 8.3 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`FilteredRela… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-1285 | Red Hat | medium | 7.5 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`django.utils… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-1207 | Red Hat | high | 8.3 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookup… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-13473 | Red Hat | low | 5.3 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
The `django.c… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67483 | Red Hat | low | 3.7 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67484 | Red Hat | medium | 4.7 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67475 | Red Hat | medium | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67476 | Red Hat | low | 4.3 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67477 | Red Hat | medium | 4.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-67479 | Red Hat | low | 0.0 | Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is as… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-11261 | Red Hat | medium | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-61645 | Red Hat | high | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2026-1801 | Red Hat | low | 5.3 | A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerabilit… | Feb 3, 2026 | Feb 3, 2026 |
| | CVE-2025-61637 | Red Hat | medium | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-61640 | Red Hat | medium | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-61642 | Red Hat | medium | 4.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-6594 | Red Hat | high | 8.1 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-6597 | Red Hat | medium | 0.0 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-6927 | Red Hat | low | 5.3 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-22778 | Red Hat | critical | 9.8 | vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-24040 | Red Hat | medium | 7.5 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Nod… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-24043 | Red Hat | medium | 5.8 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argumen… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-24133 | Red Hat | medium | 6.5 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argumen… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-24737 | Red Hat | high | 8.3 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and me… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1703 | Red Hat | low | 3.9 | When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted ou… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1764 | Red Hat | medium | 5.6 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When proce… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1765 | Red Hat | medium | 5.6 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tr… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1766 | Red Hat | medium | 5.6 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifical… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1767 | Red Hat | medium | 5.6 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracke… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2025-6208 | Red Hat | medium | 5.3 | The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolle… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1757 | Red Hat | medium | 6.2 | A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, … | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1760 | Red Hat | medium | 5.3 | A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer … | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-1761 | Red Hat | high | 8.6 | A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsin… | Feb 2, 2026 | Feb 2, 2026 |
| | CVE-2026-23035 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Pass netdev to mlx5e… | Jan 31, 2026 | Feb 3, 2026 |
| | CVE-2026-23019 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: marvell: prestera: fix NUL… | Jan 31, 2026 | Feb 3, 2026 |
| | CVE-2026-23016 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
inet: frags: drop fraglist conn… | Jan 31, 2026 | Feb 3, 2026 |
| | CVE-2025-71183 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
btrfs: always detect conflictin… | Jan 31, 2026 | Feb 3, 2026 |
| | CVE-2026-23016 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
inet: frags: drop fraglist connt… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23036 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: release path before iget_… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23018 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: release path before initi… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71185 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: ti: dma-crossbar: fix… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71187 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: sh: rz-dmac: fix devi… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23034 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/userq: Fix fence refe… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71180 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
counter: interrupt-cnt: Drop IRQ… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23033 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: omap-dma: fix dma_poo… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71184 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix NULL dereference on r… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23027 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Fix kvm_device l… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71191 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: at_hdmac: fix device … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71186 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: stm32: dmamux: fix de… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71183 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: always detect conflicting… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71190 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: bcm-sba-raid: fix dev… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23015 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gpio: mpsse: fix reference leak … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23037 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
can: etas_es58x: allow partial R… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23022 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix memory leak in idpf_vc… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23032 | Red Hat | low | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
null_blk: fix kmemleak by releas… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23024 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix memory leak of flow st… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23035 | Red Hat | medium | 5.1 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Pass netdev to mlx5e_… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23026 | Red Hat | medium | 4.1 | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom: gpi: Fix memory… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23017 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix error handling in the … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23039 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/gud: fix NULL fb and crtc de… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23030 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
phy: rockchip: inno-usb2: Fix a … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71188 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: lpc18xx-dmamux: fix d… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23031 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71181 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
rust_binder: remove spin_lock() … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23023 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
idpf: fix memory leak in idpf_vp… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23025 | Red Hat | medium | 6.3 | In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: prevent pcp corru… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23021 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: usb: pegasus: fix memory le… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23019 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: marvell: prestera: fix NULL… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23029 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Fix kvm_device l… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71189 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw: dmamux: fix OF no… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23028 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Fix kvm_device l… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23038 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
pnfs/flexfiles: Fix memory leak … | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2025-71182 | Red Hat | low | 5.1 | In the Linux kernel, the following vulnerability has been resolved:
can: j1939: make j1939_session_a… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-23020 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: 3com: 3c59x: fix possible n… | Jan 31, 2026 | Jan 31, 2026 |
| | CVE-2026-25152 | Red Hat | medium | 5.3 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node p… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2026-25153 | Red Hat | high | 7.7 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node p… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2025-24293 | Red Hat | high | 8.1 | # Active Storage allowed transformation methods potentially unsafe
Active Storage attempts to preven… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2026-25128 | Red Hat | medium | 5.3 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object wi… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2024-4027 | Red Hat | high | 7.5 | A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameter… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2026-25210 | Red Hat | medium | 6.9 | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize… | Jan 30, 2026 | Jan 30, 2026 |
| | CVE-2026-25068 | Red Hat | medium | 4.3 | alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based … | Jan 29, 2026 | Jan 29, 2026 |
| | CVE-2026-24054 | Red Hat | medium | 7.3 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtu… | Jan 29, 2026 | Jan 29, 2026 |
| | CVE-2025-62514 | Check Point | high | 8.3 | Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.… | Jan 29, 2026 | Mar 2, 2026 |
| | CVE-2020-37011 | Red Hat | medium | 5.0 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger … | Jan 29, 2026 | Jan 29, 2026 |
| | CVE-2026-24835 | Red Hat | medium | 6.6 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentic… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-61728 | Red Hat | medium | 7.5 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file i… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-61726 | Red Hat | high | 7.5 | The net/url package does not set a limit on the number of query parameters in a query. While the max… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-61731 | Red Hat | high | 8.6 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file wit… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-68119 | Red Hat | medium | 6.7 | Downloading and building modules with malicious version strings can cause local code execution. On s… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-1530 | Red Hat | high | 8.1 | A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-th… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-1531 | Red Hat | high | 8.1 | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disab… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-0818 | Red Hat | medium | 6.1 | When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded … | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-24838 | Microsoft | critical | 9.1 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e… | Jan 28, 2026 | Feb 4, 2026 |
| | CVE-2026-24842 | Red Hat | high | 8.2 | node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security c… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-24837 | Microsoft | high | 7.6 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e… | Jan 28, 2026 | Feb 4, 2026 |
| | CVE-2026-24836 | Microsoft | high | 7.6 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e… | Jan 28, 2026 | Feb 4, 2026 |
| | CVE-2026-24833 | Microsoft | high | 7.6 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e… | Jan 28, 2026 | Feb 4, 2026 |
| | CVE-2026-24784 | Microsoft | medium | 6.8 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e… | Jan 28, 2026 | Feb 4, 2026 |
| | CVE-2026-1539 | Red Hat | medium | 5.8 | A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be s… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-1518 | Red Hat | low | 2.7 | A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backc… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-1536 | Red Hat | medium | 5.8 | A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition heade… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-23014 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
perf: Ensure swevent hrtimer is … | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-57283 | Red Hat | high | 7.8 | The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs… | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2025-61140 | Red Hat | high | 8.8 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. | Jan 28, 2026 | Jan 28, 2026 |
| | CVE-2026-24779 | Red Hat | high | 7.1 | vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24765 | Red Hat | high | 7.8 | PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24747 | Red Hat | high | 8.8 | PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerabili… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24858 | Fortinet | critical | 9.8 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in… | Jan 27, 2026 | Jan 29, 2026 |
| | CVE-2026-24688 | Red Hat | medium | 5.3 | pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulne… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24883 | Red Hat | low | 3.7 | In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24882 | Red Hat | high | 8.4 | In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PK… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24881 | Red Hat | high | 8.1 | In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped s… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-22263 | Red Hat | medium | 5.3 | Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3,… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-22262 | Red Hat | medium | 5.9 | Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prep… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-23593 | HPE | high | 7.5 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could … | Jan 27, 2026 | Feb 27, 2026 |
| | CVE-2026-23592 | HPE | high | 7.2 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allo… | Jan 27, 2026 | Feb 27, 2026 |
| | CVE-2026-22261 | Red Hat | low | 3.7 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficie… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-14911 | Red Hat | medium | 6.5 | User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed Grid… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-0648 | Check Point | high | 7.8 | The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in t… | Jan 27, 2026 | Jan 29, 2026 |
| | CVE-2025-69421 | Check Point | high | 7.5 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
dereference in the PKC… | Jan 27, 2026 | Feb 28, 2026 |
| | CVE-2025-69418 | Check Point | medium | 4.0 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerate… | Jan 27, 2026 | Feb 2, 2026 |
| | CVE-2026-24869 | Red Hat | high | 7.5 | Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox <… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24868 | Red Hat | medium | 6.1 | Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 147.… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-15467 | Red Hat | high | 9.8 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD … | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-13881 | Red Hat | low | 2.7 | A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited priv… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-21721 | Red Hat | high | 8.1 | The dashboard permissions API does not verify the target dashboard scope and only checks the dashboa… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-21720 | Red Hat | high | 7.5 | Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the re… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24825 | Red Hat | medium | 5.3 | Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/y… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24686 | Red Hat | medium | 4.7 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses th… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24486 | Red Hat | high | 8.6 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Travers… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24480 | Red Hat | high | 9.9 | QGIS is a free, open source, cross platform geographical information system (GIS) The repository con… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-11187 | Red Hat | medium | 6.1 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-b… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-15468 | Red Hat | low | 5.9 | Issue summary: If an application using the SSL_CIPHER_find() function in
a QUIC protocol client or s… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-15469 | Red Hat | low | 5.5 | Issue summary: The 'openssl dgst' command-line tool silently truncates input
data to 16MB when using… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-66199 | Red Hat | low | 5.9 | Issue summary: A TLS 1.3 connection using certificate compression can be
forced to allocate a large … | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-68160 | Red Hat | low | 4.7 | Issue summary: Writing large, newline-free data into a BIO chain using the
line-buffering filter whe… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-69418 | Red Hat | low | 4.0 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerate… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-69419 | Red Hat | medium | 7.4 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
crafted PKCS#12 file with… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-69421 | Red Hat | low | 6.5 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
dereference in the PKC… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-69420 | Red Hat | low | 5.9 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response
verification code whe… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-22795 | Red Hat | low | 5.5 | Issue summary: An invalid or NULL pointer dereference can happen in
an application processing a malf… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-22796 | Red Hat | low | 5.9 | Issue summary: A type confusion vulnerability exists in the signature
verification of signed PKCS#7 … | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-1467 | Red Hat | medium | 5.8 | A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Ret… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-1484 | Red Hat | medium | 4.2 | A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to i… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-1485 | Red Hat | low | 2.8 | A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs be… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-1489 | Red Hat | medium | 5.4 | A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implement… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-28164 | Red Hat | medium | 5.0 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of s… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2025-28162 | Red Hat | medium | 6.2 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of s… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-1504 | Red Hat | high | 6.5 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowe… | Jan 27, 2026 | Jan 27, 2026 |
| | CVE-2026-24400 | Red Hat | medium | 6.1 | AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in … | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-24131 | Red Hat | medium | 6.5 | pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bi… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-24056 | Red Hat | medium | 6.5 | pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `gi… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-23890 | Red Hat | medium | 6.5 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin li… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-23889 | Red Hat | medium | 6.5 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarbal… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2025-59472 | Red Hat | medium | 5.9 | A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2025-59471 | Red Hat | medium | 5.9 | A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatter… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-23888 | Red Hat | medium | 6.5 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-21509 | Microsoft | high | 7.8 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attac… | Jan 26, 2026 | Feb 11, 2026 |
| | CVE-2025-50537 | Red Hat | medium | 5.5 | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular referenc… | Jan 26, 2026 | Jan 26, 2026 |
| | CVE-2026-23002 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
lib/buildid: use __kernel_read(… | Jan 25, 2026 | Jan 26, 2026 |
| | CVE-2026-23000 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix crash on profile… | Jan 25, 2026 | Feb 24, 2026 |
| | CVE-2026-22998 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix NULL pointer dere… | Jan 25, 2026 | Feb 26, 2026 |
| | CVE-2026-22997 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: can: j1939: j1939_xtp_rx_rt… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23005 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
x86/fpu: Clear XSTATE_BV[i] in g… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23012 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: remove call_contr… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23004 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
dst: fix races in rt6_uncached_l… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-22996 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Don't store mlx5e_pri… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23001 | Red Hat | medium | 7.8 | In the Linux kernel, the following vulnerability has been resolved:
macvlan: fix possible UAF in mac… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2025-71162 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: tegra-adma: Fix use-a… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23002 | Red Hat | low | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
lib/buildid: use __kernel_read()… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-22999 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_qfq: do not free … | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23013 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
net: octeon_ep_vf: fix free_irq … | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23009 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
xhci: sideband: don't dereferenc… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-22998 | Red Hat | medium | 6.4 | In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix NULL pointer deref… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23006 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ASoC: tlv320adcx140: fix null po… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23011 | Red Hat | medium | 6.6 | In the Linux kernel, the following vulnerability has been resolved:
ipv4: ip_gre: make ipgre_header(… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23007 | Red Hat | low | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
block: zero non-PI portion of au… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23008 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix KMS with 3D on H… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23010 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix use-after-free in inet… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23000 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix crash on profile … | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2025-71163 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix device leak… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-23003 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: use skb_vlan_inet_pr… | Jan 25, 2026 | Jan 25, 2026 |
| | CVE-2026-24401 | Red Hat | medium | 6.5 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protoco… | Jan 24, 2026 | Jan 24, 2026 |
| | CVE-2026-1386 | Red Hat | medium | 6.0 | A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and ear… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-1299 | Red Hat | medium | 7.1 | The
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22991 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
libceph: make free_choose_arg_m… | Jan 23, 2026 | Feb 26, 2026 |
| | CVE-2026-22982 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: mscc: ocelot: Fix crash wh… | Jan 23, 2026 | Feb 26, 2026 |
| | CVE-2026-22981 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
idpf: detach and close netdevs … | Jan 23, 2026 | Feb 26, 2026 |
| | CVE-2025-71160 | Check Point | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: avoid cha… | Jan 23, 2026 | Feb 26, 2026 |
| | CVE-2026-0994 | Red Hat | high | 7.5 | A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python,… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-24515 | Red Hat | low | 2.9 | In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-0775 | Red Hat | high | 7.0 | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-15059 | Red Hat | high | 7.8 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-24137 | Red Hat | medium | 5.8 | sigstore framework is a common go library shared across sigstore services and clients. In versions 1… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71145 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
usb: phy: isp1301: fix non-OF de… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71156 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
gve: defer interrupt enabling un… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71149 | Red Hat | low | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
io_uring/poll: correctly handle … | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71152 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: dsa: properly keep track of… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71157 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: always drop device re… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71146 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conncount: fix lea… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71151 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory and information… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71153 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Fix memory leak in get_fi… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71150 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Fix refcount leak when in… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71155 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: Fix gmap_helper_zap_o… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71147 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Fix a memory leak… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71148 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/handshake: restore destructo… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71154 | Red Hat | low | 4.0 | In the Linux kernel, the following vulnerability has been resolved:
net: usb: rtl8150: fix memory le… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22989 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
nfsd: check that server is runni… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22988 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
arp: do not assume dev_hard_head… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22993 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
idpf: Fix RSS LUT NULL ptr issue… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22987 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_api: avoid derefe… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71159 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix use-after-free warnin… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22995 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ublk: fix use-after-free in ublk… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22985 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
idpf: Fix RSS LUT NULL pointer c… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22978 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
wifi: avoid kernel-infoleak from… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22991 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
libceph: make free_choose_arg_ma… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22980 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
nfsd: provide locking for v4_end… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22981 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
idpf: detach and close netdevs w… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22992 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
libceph: return the handler erro… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22984 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
libceph: prevent potential out-o… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22986 | Red Hat | medium | 5.3 | In the Linux kernel, the following vulnerability has been resolved:
gpiolib: fix race condition for … | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71160 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: avoid chai… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22982 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: mscc: ocelot: Fix crash whe… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71158 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
gpio: mpsse: ensure worker is to… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22994 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix reference count leak in… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22983 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: do not write to msg_get_inq… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22990 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
libceph: replace overzealous BUG… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2025-71161 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
dm-verity: disable recursive for… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-22979 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: fix memory leak in skb_segm… | Jan 23, 2026 | Jan 23, 2026 |
| | CVE-2026-21264 | Microsoft | critical | 9.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ac… | Jan 22, 2026 | Feb 3, 2026 |
| | CVE-2026-24117 | Red Hat | medium | 5.3 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigge… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20912 | Red Hat | critical | 9.1 | Gitea does not properly validate repository ownership when linking attachments to releases. An attac… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20897 | Red Hat | critical | 9.1 | Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20888 | Red Hat | medium | 4.3 | Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interf… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20904 | Red Hat | medium | 6.5 | Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated use… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20883 | Red Hat | medium | 6.5 | Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20736 | Red Hat | high | 7.5 | Gitea does not properly verify repository context when deleting attachments. A user who previously u… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-0798 | Red Hat | low | 3.5 | Gitea may send release notification emails for private repositories to users whose access has been r… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-20750 | Red Hat | critical | 9.1 | Gitea does not properly validate project ownership in organization project operations. A user with p… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23831 | Red Hat | medium | 5.3 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementa… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2025-22234 | Red Hat | medium | 5.3 | The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in Da… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-1260 | Red Hat | high | 7.8 | Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, … | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2025-15523 | Red Hat | medium | 4.4 | MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and … | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-1225 | Red Hat | medium | 5.0 | ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including versi… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2025-71176 | Red Hat | medium | 6.8 | pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, whic… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-24049 | Red Hat | high | 7.1 | wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-24006 | Red Hat | high | 7.5 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-24001 | Red Hat | high | 7.5 | jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and … | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23992 | Red Hat | medium | 5.9 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to … | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23991 | Red Hat | medium | 5.9 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to … | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23957 | Red Hat | high | 7.5 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23956 | Red Hat | high | 7.5 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23952 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versi… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23873 | Microsoft | critical | 9.0 | hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. A… | Jan 22, 2026 | Feb 27, 2026 |
| | CVE-2026-23893 | Red Hat | medium | 6.8 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above a… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2025-67221 | Red Hat | medium | 5.5 | The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON docu… | Jan 22, 2026 | Jan 22, 2026 |
| | CVE-2026-23737 | Red Hat | high | 7.5 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-23736 | Red Hat | high | 7.3 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-24048 | Red Hat | low | 3.5 | Backstage is an open framework for building developer portals, and @backstage/backend-defaults provi… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-24047 | Red Hat | medium | 6.3 | Backstage is an open framework for building developer portals, and @backstage/cli-common provides co… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-24046 | Red Hat | high | 9.1 | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archi… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-23960 | Red Hat | high | 7.1 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-22822 | Red Hat | high | 8.8 | External Secrets Operator reads information from a third-party service and automatically injects the… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-22807 | Red Hat | high | 8.8 | vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-12781 | Red Hat | medium | 5.3 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-13465 | Red Hat | high | 8.2 | Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omi… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-20109 | Cisco | medium | 4.8 | Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Ente… | Jan 21, 2026 | Jan 26, 2026 |
| | CVE-2026-20092 | Cisco | medium | 6.0 | A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow… | Jan 21, 2026 | Jan 26, 2026 |
| | CVE-2026-20080 | Cisco | medium | 5.3 | A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could al… | Jan 21, 2026 | Jan 26, 2026 |
| | CVE-2026-20055 | Cisco | medium | 4.8 | Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Ente… | Jan 21, 2026 | Jan 26, 2026 |
| | CVE-2026-20045 | Cisco | high | 8.2 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M… | Jan 21, 2026 | Feb 13, 2026 |
| | CVE-2026-22022 | Red Hat | medium | 6.5 | Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-22444 | Red Hat | medium | 6.5 | The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some AP… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-22977 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: sock: fix hardened usercopy… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-22976 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_qfq: Fix NULL der… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-14559 | Red Hat | medium | 6.5 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issua… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-1035 | Red Hat | low | 3.1 | A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenMa… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-13878 | Red Hat | high | 7.5 | Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.
This issue affects BIND 9 v… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-66960 | Red Hat | medium | 7.5 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/g… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2025-66959 | Red Hat | medium | 7.5 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF deco… | Jan 21, 2026 | Jan 21, 2026 |
| | CVE-2026-0672 | Red Hat | medium | 4.8 | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTT… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-15367 | Red Hat | medium | 7.1 | The poplib module, when passed a user-controlled command, can have
additional commands injected usin… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-15366 | Red Hat | medium | 7.1 | The imaplib module, when passed a user-controlled command, can have additional commands injected usi… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-15282 | Red Hat | medium | 4.8 | User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newli… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-0865 | Red Hat | medium | 4.5 | User-controlled header names and values containing newlines can allow injecting HTTP headers. | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21925 | Red Hat | medium | 4.8 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21932 | Red Hat | high | 7.4 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21933 | Red Hat | medium | 6.1 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21945 | Red Hat | high | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-11468 | Red Hat | medium | 4.5 | When folding a long comment in an email header containing exclusively unfoldable characters, the par… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-55132 | Red Hat | low | 2.8 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be change… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21637 | Red Hat | medium | 5.9 | A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS … | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21636 | Red Hat | medium | 5.8 | A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network r… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-59466 | Red Hat | medium | 5.9 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors b… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-59464 | Red Hat | medium | 6.5 | A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to … | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-59465 | Red Hat | high | 7.5 | A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash b… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-55131 | Red Hat | high | 7.1 | A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are int… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-55130 | Red Hat | high | 7.1 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-w… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-33230 | Red Hat | medium | 6.1 | NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker co… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-33229 | Red Hat | medium | 6.1 | NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-33228 | Red Hat | medium | 6.6 | NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could ca… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-15281 | Red Hat | low | 5.9 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to … | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-14369 | Red Hat | medium | 5.0 | dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability fla… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-23876 | Red Hat | high | 8.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-23874 | Red Hat | medium | 5.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versi… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-22770 | Red Hat | medium | 6.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. The B… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-23950 | Red Hat | high | 8.8 | node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-23949 | Red Hat | high | 8.6 | jaraco.context, an open-source software package that provides some useful decorators and context man… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2024-31884 | Red Hat | medium | 6.5 | No description is available for this CVE. | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2025-56005 | Red Hat | high | 7.8 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Exec… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21952 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21941 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21948 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21950 | Red Hat | medium | 6.5 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21936 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21968 | Red Hat | medium | 6.5 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21937 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21929 | Red Hat | medium | 5.3 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ve… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21965 | Red Hat | low | 2.7 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supp… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21964 | Red Hat | medium | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supp… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-21949 | Red Hat | medium | 6.5 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported… | Jan 20, 2026 | Jan 20, 2026 |
| | CVE-2026-23833 | Red Hat | low | 7.5 | ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23884 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen … | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23883 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointe… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23732 | Red Hat | medium | 6.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph … | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23534 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-s… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23533 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-s… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23532 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-s… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23531 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCo… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-23530 | Red Hat | high | 7.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bi… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2025-68616 | Red Hat | high | 7.5 | WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side reques… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-0603 | Red Hat | high | 8.3 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQ… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-1190 | Red Hat | low | 3.1 | A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-1200 | Red Hat | medium | 6.3 | A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmenta… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-1145 | Red Hat | high | 6.3 | A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the func… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-1144 | Red Hat | high | 6.3 | A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of … | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-1180 | Red Hat | medium | 5.8 | A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients … | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2026-22797 | Red Hat | high | 9.9 | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10… | Jan 19, 2026 | Jan 19, 2026 |
| | CVE-2025-15538 | Red Hat | medium | 5.3 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected… | Jan 18, 2026 | Jan 18, 2026 |
| | CVE-2025-15537 | Red Hat | medium | 5.3 | A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function ma… | Jan 18, 2026 | Jan 18, 2026 |
| | CVE-2025-15536 | Red Hat | medium | 5.3 | A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function… | Jan 18, 2026 | Jan 18, 2026 |
| | CVE-2025-15534 | Red Hat | medium | 5.3 | A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the functi… | Jan 18, 2026 | Jan 18, 2026 |
| | CVE-2025-15533 | Red Hat | medium | 5.3 | A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is th… | Jan 18, 2026 | Jan 18, 2026 |
| | CVE-2026-21223 | Microsoft | high | 7.1 | Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to by… | Jan 16, 2026 | Feb 22, 2026 |
| | CVE-2026-20960 | Microsoft | high | 8.0 | Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a … | Jan 16, 2026 | Feb 12, 2026 |
| | CVE-2026-23745 | Red Hat | high | 8.2 | node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Lin… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2021-47839 | Red Hat | high | — | Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2026-23490 | Red Hat | high | 7.5 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been fou… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2025-29943 | Red Hat | low | 3.2 | Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the confi… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2026-0858 | Red Hat | medium | 6.1 | Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored X… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2025-24531 | Red Hat | medium | 6.7 | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error s… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2025-62291 | Red Hat | high | 8.1 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server… | Jan 16, 2026 | Jan 16, 2026 |
| | CVE-2026-22045 | Red Hat | medium | 5.9 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0915 | Red Hat | medium | 5.3 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's … | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-1002 | Red Hat | medium | 5.3 | The Vert.x Web static handler component cache can be manipulated to deny the access to static files … | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2025-15265 | Red Hat | medium | 6.1 | An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-23527 | Red Hat | high | 8.9 | H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there … | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-23766 | Red Hat | medium | — | No description is available for this CVE. | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-22775 | Red Hat | high | 7.5 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-22774 | Red Hat | high | 7.5 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2025-9014 | Check Point | high | 7.5 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-… | Jan 15, 2026 | Jan 30, 2026 |
| | CVE-2026-20076 | Cisco | medium | 4.8 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could … | Jan 15, 2026 | Jan 30, 2026 |
| | CVE-2026-20075 | Cisco | medium | 4.8 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager … | Jan 15, 2026 | Jan 30, 2026 |
| | CVE-2026-20047 | Cisco | medium | 4.8 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Ci… | Jan 15, 2026 | Jan 30, 2026 |
| | CVE-2025-61973 | Microsoft | high | 8.8 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via th… | Jan 15, 2026 | Jan 16, 2026 |
| | CVE-2026-0897 | Red Hat | high | 7.6 | Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google … | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0976 | Red Hat | low | 3.7 | A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak a… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0988 | Red Hat | low | 3.7 | A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0989 | Red Hat | low | 3.7 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0990 | Red Hat | medium | 5.9 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occur… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0992 | Red Hat | low | 2.9 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs… | Jan 15, 2026 | Jan 15, 2026 |
| | CVE-2026-0861 | Red Hat | low | 8.1 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-0961 | Red Hat | medium | 5.5 | BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-0962 | Red Hat | medium | 5.3 | SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-0960 | Red Hat | medium | 4.7 | HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-0959 | Red Hat | medium | 5.3 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial o… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22036 | Red Hat | low | 3.7 | Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the dec… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22859 | Red Hat | high | 7.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client … | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22858 | Red Hat | high | 7.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-over… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22857 | Red Hat | medium | 5.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-f… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22856 | Red Hat | medium | 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the seri… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22855 | Red Hat | high | 7.4 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-boun… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22854 | Red Hat | medium | 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-over… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22853 | Red Hat | high | 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22852 | Red Hat | medium | 5.6 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP se… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-22851 | Red Hat | medium | 5.0 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition b… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71144 | F5 | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
mptcp: ensure context reset on … | Jan 14, 2026 | Feb 26, 2026 |
| | CVE-2025-71138 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm/dpu: Add missing NULL p… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71133 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: avoid invalid read … | Jan 14, 2026 | Jan 19, 2026 |
| | CVE-2025-71130 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Zero-initialize t… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71125 | F5 | medium | — | In the Linux kernel, the following vulnerability has been resolved:
tracing: Do not register unsupp… | Jan 14, 2026 | Jan 19, 2026 |
| | CVE-2025-71124 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm/a6xx: move preempt_prep… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71118 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ACPICA: Avoid walking the Names… | Jan 14, 2026 | Jan 19, 2026 |
| | CVE-2025-71103 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm: adreno: fix deferencin… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-66169 | Red Hat | medium | 5.3 | Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Came… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2026-0532 | Red Hat | high | 8.6 | External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) c… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-14242 | Red Hat | medium | 6.5 | A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overf… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-56226 | Red Hat | medium | 5.3 | Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function withi… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71111 | Red Hat | low | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
hwmon: (w83791d) Convert macros … | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71139 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
kernel/kexec: fix IMA when alloc… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71143 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
clk: samsung: exynos-clkout: Ass… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71140 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
media: mediatek: vcodec: Use spi… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71104 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix VM hard lockup aft… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71138 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm/dpu: Add missing NULL po… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71114 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
via_wdt: fix critical boot hang … | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71144 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mptcp: ensure context reset on d… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71135 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
md/raid5: fix possible null-poin… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71134 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: change all pagebl… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71131 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
crypto: seqiv - Do not use req->… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71112 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
net: hns3: add VLAN id validatio… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71110 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mm/slub: reset KASAN tag in defe… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71127 | Red Hat | medium | 6.3 | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: Discard Beacon f… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71117 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
block: Remove queue freezing fro… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71129 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfun… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71136 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
media: adv7842: Avoid possible o… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71133 | Red Hat | low | 3.1 | In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: avoid invalid read i… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71105 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: use global inline_xattr_sl… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71106 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
fs: PM: Fix reverse check in fil… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71123 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
ext4: fix string copying in pars… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71125 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
tracing: Do not register unsuppo… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71115 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
um: init cpu_tasks[] earlier
Thi… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71109 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
MIPS: ftrace: Fix memory corrupt… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71124 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm/a6xx: move preempt_prepa… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71103 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/msm: adreno: fix deferencing… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71116 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
libceph: make decode_pool() more… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71132 | Red Hat | medium | 4.7 | In the Linux kernel, the following vulnerability has been resolved:
smc91x: fix broken irq-context i… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71119 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
powerpc/kexec: Enable SMT before… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71130 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Zero-initialize th… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71118 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ACPICA: Avoid walking the Namesp… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71120 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: svcauth_gss: avoid NULL … | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71121 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
parisc: Do not reprogram affinit… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71107 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: ensure node page reads com… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71137 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix "UBSAN: shift-… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71113 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - zero initialize… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71108 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Handle incorre… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71142 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
cpuset: fix warning when disabli… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71126 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid deadlock on fallbac… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71122 | Red Hat | low | 2.5 | In the Linux kernel, the following vulnerability has been resolved:
iommufd/selftest: Check for over… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71128 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
erspan: Initialize options_len b… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71102 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scs: fix a wrong parameter in __… | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-71141 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/tilcdc: Fix removal actions … | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-70968 | Red Hat | high | 9.8 | FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). | Jan 14, 2026 | Jan 14, 2026 |
| | CVE-2025-37186 | HPE | high | 7.8 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual I… | Jan 13, 2026 | Mar 2, 2026 |
| | CVE-2026-0543 | Red Hat | medium | 6.5 | Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Exc… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0531 | Red Hat | medium | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0530 | Red Hat | medium | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-22791 | Red Hat | medium | 6.6 | openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-21265 | Microsoft | medium | 6.4 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificate… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20963 | Microsoft | high | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20959 | Microsoft | medium | 4.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20958 | Microsoft | medium | 5.4 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to d… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20957 | Microsoft | high | 7.8 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to … | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20956 | Microsoft | high | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20955 | Microsoft | high | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20953 | Microsoft | high | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20952 | Microsoft | high | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20951 | Microsoft | high | 7.8 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute … | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20950 | Microsoft | high | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2026-20949 | Microsoft | high | 7.8 | Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a securi… | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20948 | Microsoft | high | 7.8 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co… | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20947 | Microsoft | high | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Of… | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20946 | Microsoft | high | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally… | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20944 | Microsoft | high | 8.4 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20943 | Microsoft | high | 7.0 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 | Jan 16, 2026 |
| | CVE-2026-20822 | Microsoft | high | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2025-37166 | HPE | high | 7.5 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device… | Jan 13, 2026 | Feb 26, 2026 |
| | CVE-2025-37165 | HPE | high | 7.5 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain net… | Jan 13, 2026 | Mar 2, 2026 |
| | CVE-2025-67685 | Fortinet | low | 3.8 | A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox … | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2025-64155 | Fortinet | critical | 9.8 | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Jan 13, 2026 | Jan 20, 2026 |
| | CVE-2025-59922 | Fortinet | high | 7.2 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerabilit… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2025-58693 | Fortinet | medium | 6.5 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2025-47855 | Fortinet | critical | 9.8 | An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet Fo… | Jan 13, 2026 | Jan 14, 2026 |
| | CVE-2025-25249 | Fortinet | high | 8.1 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 th… | Jan 13, 2026 | Feb 23, 2026 |
| | CVE-2025-71096 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Check for the presen… | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2025-71087 | F5 | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iavf: fix off-by-one issues in … | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2025-71074 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
functionfs: fix the open/remova… | Jan 13, 2026 | Jan 23, 2026 |
| | CVE-2025-68820 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ext4: xattr: fix null pointer d… | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2025-68818 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
scsi: Revert "scsi: qla2xxx: Pe… | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2025-68797 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
char: applicom: fix NULL pointe… | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2025-68776 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net/hsr: fix NULL pointer deref… | Jan 13, 2026 | Jan 19, 2026 |
| | CVE-2026-0891 | Red Hat | high | 7.5 | Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0890 | Red Hat | low | 3.4 | Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability affects Firefo… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0892 | Red Hat | medium | 6.1 | Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0888 | Red Hat | low | 3.4 | Information disclosure in the XML component. This vulnerability affects Firefox < 147 and Thunderbir… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0889 | Red Hat | low | 3.4 | Denial-of-service in the DOM: Service Workers component. This vulnerability affects Firefox < 147 an… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0887 | Red Hat | medium | 6.1 | Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects F… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0886 | Red Hat | medium | 6.1 | Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, F… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0885 | Red Hat | medium | 6.1 | Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 147, Firefox ES… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0884 | Red Hat | medium | 6.1 | Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147, Firefox… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0883 | Red Hat | medium | 6.1 | Information disclosure in the Networking component. This vulnerability affects Firefox < 147, Firefo… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0882 | Red Hat | high | 7.5 | Use-after-free in the IPC component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32,… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0881 | Red Hat | high | 7.5 | Sandbox escape in the Messaging System component. This vulnerability affects Firefox < 147 and Thund… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0879 | Red Hat | high | 7.5 | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability af… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0880 | Red Hat | high | 7.5 | Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0878 | Red Hat | high | 7.5 | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vul… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0877 | Red Hat | high | 7.5 | Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 147, Firefox … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0503 | Check Point | medium | 6.4 | Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP E… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68783 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-mixer: us16x08: valida… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68812 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
media: iris: Add sanity check fo… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71085 | Red Hat | medium | 7.5 | In the Linux kernel, the following vulnerability has been resolved:
ipv6: BUG() in pskb_expand_head(… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71080 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix a BUG in rt6_get_pcpu_… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68780 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
sched/deadline: only set free_cp… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68778 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
btrfs: don't log conflicting ino… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68795 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ethtool: Avoid overflowing users… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68774 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
hfsplus: fix missing hfs_bnode_g… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68781 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
usb: phy: fsl-usb: Fix use-after… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71097 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ipv4: Fix reference count leak w… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71066 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: Always remove cl… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71084 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
RDMA/cm: Fix leaking the multica… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71071 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iommu/mediatek: fix use-after-fr… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68791 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
fuse: missing copy_finish in fus… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68794 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
iomap: adjust read range correct… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68796 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid updating zero… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68810 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
KVM: Disallow toggling KVM_MEM_G… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71068 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
svcrdma: bound check rq_pages in… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71075 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: aic94xx: fix use-after-fre… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68801 | Red Hat | medium | 5.6 | In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_router: Fix neig… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71100 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
wifi: rtlwifi: 8192cu: fix tid o… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68770 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix XDP_TX path
For XDP… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71076 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/xe/oa: Limit num_syncs to pr… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71088 | Red Hat | medium | 4.1 | In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simul… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71087 | Red Hat | medium | 6.6 | In the Linux kernel, the following vulnerability has been resolved:
iavf: fix off-by-one issues in i… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68822 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
Input: alps - fix use-after-free… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71082 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: revert use of … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68777 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
Input: ti_am335x_tsc - fix off-b… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68809 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: vfs: fix race on m_flags … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68821 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
fuse: fix readahead reclaim dead… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71101 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/x86: hp-bioscfg: Fix ou… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71099 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/xe/oa: Fix potential UAF in … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71090 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix nfsd_file reference le… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68788 | Red Hat | low | 2.5 | In the Linux kernel, the following vulnerability has been resolved:
fsnotify: do not generate ACCESS… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71074 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
functionfs: fix the open/removal… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68775 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
net/handshake: duplicate handsha… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68773 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
spi: fsl-cpm: Check length parit… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68800 | Red Hat | medium | 7.3 | In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_mr: Fix use-afte… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68767 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
hfsplus: Verify inode mode when … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71081 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ASoC: stm32: sai: fix OF node le… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68803 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
NFSD: NFSv4 file creation neglec… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68807 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
block: fix race between wbt_enab… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68784 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
xfs: fix a UAF problem in xattr … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68769 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix return value of f2fs_r… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68818 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
scsi: Revert "scsi: qla2xxx: Per… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71096 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Check for the presenc… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68779 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Avoid unregistering P… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68819 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: dtv5100: fix out… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71073 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
Input: lkkbd - disable pending w… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68816 | Red Hat | medium | 5.6 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: fw_tracer, Validate fo… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68798 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
perf/x86/amd: Check event before… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71067 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ntfs: set dummy blocksize to rea… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68793 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix a job->pasid acc… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68814 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix filename leak in _… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71072 | Red Hat | low | 2.5 | In the Linux kernel, the following vulnerability has been resolved:
shmem: fix recovery on rename fa… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68823 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ublk: fix deadlock when reading … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68782 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
scsi: target: Reset t_task_cdb p… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71070 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
ublk: clean up user copy referen… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71069 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: invalidate dentry cache on… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68792 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
tpm2-sessions: Fix out of range … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68813 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ipvs: fix ipv4 null-ptr-deref in… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68787 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
netrom: Fix memory leak in nr_se… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68815 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: Remove drr class… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68768 | Red Hat | medium | 4.4 | In the Linux kernel, the following vulnerability has been resolved:
inet: frags: flush pending skbs … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68772 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid updating comp… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71086 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: rose: fix invalid array ind… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71098 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
ip6_gre: make ip6gre_header() ro… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68820 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ext4: xattr: fix null pointer de… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68817 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in ksm… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71078 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
powerpc/64s/slb: Fix SLB multihi… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68776 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/hsr: fix NULL pointer derefe… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68808 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: initialize local p… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71077 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
tpm: Cap the number of PCR banks… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68790 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix double unregister … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68797 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
char: applicom: fix NULL pointer… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71089 | Red Hat | medium | 7.8 | In the Linux kernel, the following vulnerability has been resolved:
iommu: disable SVA when CONFIG_X… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68805 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
fuse: fix io-uring list corrupti… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68786 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: skip lock-range check on … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71083 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/ttm: Avoid NULL pointer dere… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68806 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix buffer validation by … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71064 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: hns3: using the num_tqps in… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68799 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
caif: fix integer underflow in c… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71092 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Fix OOB write in b… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71091 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
team: fix check for port enabled… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71093 | Red Hat | medium | 6.5 | In the Linux kernel, the following vulnerability has been resolved:
e1000: fix OOB in e1000_tbi_shou… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68771 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix kernel BUG in ocfs2_f… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68789 | Red Hat | medium | — | No description is available for this CVE. | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68811 | Red Hat | medium | 7.1 | In the Linux kernel, the following vulnerability has been resolved:
svcrdma: use rc_pageoff for memc… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71065 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid potential dea… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68785 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix middle att… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71095 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: fix the crash issue… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68804 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_ishtp: … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71079 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: nfc: fix deadlock between n… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-68802 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Limit num_syncs to preve… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-71094 | Red Hat | medium | 4.0 | In the Linux kernel, the following vulnerability has been resolved:
net: usb: asix: validate PHY add… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0900 | Red Hat | high | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0907 | Red Hat | low | 4.3 | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacke… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0905 | Red Hat | medium | 6.5 | Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0904 | Red Hat | medium | 6.5 | Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remot… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0902 | Red Hat | medium | 6.5 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0899 | Red Hat | high | 8.8 | Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker … | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2026-0908 | Red Hat | low | — | Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potenti… | Jan 13, 2026 | Jan 13, 2026 |
| | CVE-2025-15514 | Check Point | high | 7.5 | Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in… | Jan 12, 2026 | Jan 21, 2026 |
| | CVE-2024-58340 | Red Hat | medium | 5.3 | LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) … | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2025-15514 | Red Hat | high | 7.5 | Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2026-22801 | Red Hat | medium | 6.6 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portabl… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2026-22695 | Red Hat | medium | 6.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portabl… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2026-22772 | Red Hat | medium | 5.8 | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC)… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2026-22776 | Red Hat | high | 7.5 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2026-22771 | Red Hat | high | 8.8 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2025-68471 | Red Hat | medium | 6.5 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protoco… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2025-68468 | Red Hat | medium | 6.5 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protoco… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2025-68276 | Red Hat | medium | 5.5 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protoco… | Jan 12, 2026 | Jan 12, 2026 |
| | CVE-2025-68493 | Apache | high | 8.1 | Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Str… | Jan 11, 2026 | Mar 11, 2026 |
| | CVE-2025-68493 | Red Hat | high | 7.1 | Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Stru… | Jan 11, 2026 | Jan 11, 2026 |
| | CVE-2026-0824 | Red Hat | medium | 3.5 | A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of t… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-0822 | Red Hat | high | 6.3 | A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function j… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-0821 | Red Hat | high | 7.3 | A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the fu… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22773 | Red Hat | medium | 6.5 | vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to … | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22699 | Check Point | high | 7.5 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including … | Jan 10, 2026 | Jan 22, 2026 |
| | CVE-2026-22693 | Check Point | medium | 5.3 | HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability… | Jan 10, 2026 | Feb 18, 2026 |
| | CVE-2026-22703 | Red Hat | medium | 5.5 | Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 a… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22702 | Red Hat | medium | 4.5 | virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TO… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22701 | Red Hat | medium | 5.3 | filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race cond… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22693 | Red Hat | medium | 5.3 | HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22691 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible … | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22690 | Red Hat | medium | 6.5 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible … | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22610 | Red Hat | medium | 7.3 | Angular is a development platform for building mobile and desktop web applications using TypeScript/… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22030 | Red Hat | medium | 6.5 | React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-22029 | Red Hat | high | 8.0 | React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2026-21884 | Red Hat | high | 8.2 | React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2025-61686 | Red Hat | critical | 9.1 | React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/d… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2025-59057 | Red Hat | high | 7.6 | React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-ro… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2025-68470 | Red Hat | medium | 6.5 | React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an att… | Jan 10, 2026 | Jan 10, 2026 |
| | CVE-2025-9222 | Red Hat | high | 8.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2025-13772 | Red Hat | high | 7.1 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 bef… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2025-13761 | Red Hat | high | 8.0 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 1… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2025-70974 | Red Hat | critical | 10.0 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2025-14525 | Red Hat | medium | 6.4 | A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, ca… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2026-0665 | Red Hat | medium | 6.5 | An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw… | Jan 9, 2026 | Jan 9, 2026 |
| | CVE-2025-14505 | Red Hat | medium | 5.6 | The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value … | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-68158 | Red Hat | medium | 5.7 | Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prio… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-68151 | Red Hat | medium | 5.3 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implem… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-67858 | Red Hat | high | 7.8 | A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity los… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-67603 | Red Hat | medium | 7.3 | A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall c… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-22028 | Red Hat | medium | 6.1 | Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DO… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-21895 | Red Hat | low | 5.5 | The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a R… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-14459 | Red Hat | high | 8.5 | A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to … | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-14017 | Red Hat | medium | 4.8 | When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one … | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-21883 | Red Hat | medium | 5.4 | Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a s… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-12543 | Red Hat | high | 9.6 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Ja… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-66560 | Red Hat | medium | 5.9 | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-0716 | Red Hat | medium | 4.8 | A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-d… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-0719 | Red Hat | high | 8.6 | A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-50334 | Red Hat | high | 7.5 | An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via t… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2025-65518 | Red Hat | high | 7.5 | Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition.… | Jan 8, 2026 | Jan 8, 2026 |
| | CVE-2026-21869 | Red Hat | high | 8.1 | llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_disc… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-62224 | Microsoft | medium | 5.5 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows a… | Jan 7, 2026 | Feb 2, 2026 |
| | CVE-2026-21441 | Red Hat | high | 7.5 | urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient … | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-69264 | Red Hat | high | 8.8 | pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute ar… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-69263 | Red Hat | high | 7.5 | pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hoste… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-13151 | Red Hat | low | 5.9 | Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-22185 | Red Hat | medium | 6.8 | OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commi… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-22184 | Red Hat | high | 8.6 | zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility loca… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-69262 | Red Hat | medium | 7.5 | pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability wh… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-0669 | Red Hat | medium | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wiki… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-0668 | Red Hat | medium | 6.5 | Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualDa… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-20029 | Cisco | medium | 4.9 | A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE… | Jan 7, 2026 | Jan 8, 2026 |
| | CVE-2026-20027 | Cisco | medium | 5.3 | Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that c… | Jan 7, 2026 | Jan 8, 2026 |
| | CVE-2025-67366 | Check Point | high | 7.5 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. … | Jan 7, 2026 | Jan 29, 2026 |
| | CVE-2025-67364 | Check Point | high | 7.5 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file opera… | Jan 7, 2026 | Jan 29, 2026 |
| | CVE-2025-9611 | Microsoft | medium | — | Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on inco… | Jan 7, 2026 | Jan 8, 2026 |
| | CVE-2026-25211 | Red Hat | low | 3.8 | Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initializ… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2026-0707 | Red Hat | medium | 5.3 | A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regardin… | Jan 7, 2026 | Jan 7, 2026 |
| | CVE-2025-13812 | Check Point | medium | 4.3 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plug… | Jan 6, 2026 | Jan 8, 2026 |
| | CVE-2025-15444 | Check Point | critical | 9.8 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libso… | Jan 6, 2026 | Mar 10, 2026 |
| | CVE-2025-15444 | Red Hat | medium | 6.8 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libso… | Jan 6, 2026 | Jan 6, 2026 |
| | CVE-2025-69230 | Red Hat | low | 5.4 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 a… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69229 | Red Hat | medium | 5.8 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 a… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69228 | Red Hat | medium | 6.8 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69227 | Red Hat | medium | 7.5 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69225 | Red Hat | low | 5.4 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69226 | Red Hat | medium | 5.3 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69224 | Red Hat | medium | 5.4 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-69223 | Red Hat | high | 7.5 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68428 | Red Hat | high | 8.6 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-66648 | Red Hat | high | 7.2 | vega-functions provides function implementations for the Vega expression language. Prior to version … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-65110 | Red Hat | high | 8.1 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68762 | Check Point | medium | — | In the Linux kernel, the following vulnerability has been resolved:
net: netpoll: initialize work q… | Jan 5, 2026 | Jan 8, 2026 |
| | CVE-2025-68760 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix potential out-of-… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68766 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
irqchip/mchp-eic: Fix error code… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68754 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
rtc: amlogic-a4: fix double free… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68761 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
hfs: fix potential use after fre… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68753 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-motu: add bounds … | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68756 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
block: Use RCU in blk_mq_[un]qui… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68765 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
mt76: mt7615: Fix memory leak in… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68755 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
staging: most: remove broken i2c… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68751 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
s390/fpu: Fix false-positive kms… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68764 | Red Hat | medium | 6.1 | In the Linux kernel, the following vulnerability has been resolved:
NFS: Automounted filesystems sho… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68759 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
wifi: rtl818x: Fix potential mem… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68763 | Red Hat | medium | — | In the Linux kernel, the following vulnerability has been resolved:
crypto: starfive - Correctly han… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68758 | Red Hat | low | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
backlight: led-bl: Add devlink t… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68762 | Red Hat | low | 3.3 | In the Linux kernel, the following vulnerability has been resolved:
net: netpoll: initialize work qu… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68752 | Red Hat | medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved:
iavf: Implement settime64 with -… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2025-68757 | Red Hat | medium | 6.2 | In the Linux kernel, the following vulnerability has been resolved:
drm/vgem-fence: Fix potential de… | Jan 5, 2026 | Jan 5, 2026 |
| | CVE-2026-21444 | Red Hat | medium | 6.5 | libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in vers… | Jan 2, 2026 | Jan 2, 2026 |
| | CVE-2025-67269 | Red Hat | high | 7.5 | An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd v… | Jan 2, 2026 | Jan 2, 2026 |
| | CVE-2025-67268 | Red Hat | high | 7.5 | gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/dr… | Jan 2, 2026 | Jan 2, 2026 |
| | CVE-2025-15412 | Red Hat | medium | 7.1 | A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the … | Jan 1, 2026 | Jan 1, 2026 |
| | CVE-2025-15411 | Red Hat | medium | 7.1 | A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the func… | Jan 1, 2026 | Jan 1, 2026 |
| | CVE-2026-21428 | Red Hat | high | 8.7 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0… | Jan 1, 2026 | Jan 1, 2026 |
| | CVE-2025-11157 | Red Hat | high | 7.8 | A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specif… | Jan 1, 2026 | Jan 1, 2026 |
| | CVE-2025-69413 | Red Hat | medium | 5.3 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on … | Jan 1, 2026 | Jan 1, 2026 |