| | CVE-2026-21228 | Microsoft | high | 8.1 | 0.1%
| | Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21222 | Microsoft | medium | 5.5 | 0.0%
| | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-20846 | Microsoft | high | 7.5 | 0.0%
| | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-20841 | Microsoft | high | 7.8 | 0.1%
| | Improper neutralization of special elements used in a command ('command injection') in Windows Notep… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-0964 | Red Hat | medium | 5.0 | — | | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0968 | Red Hat | low | 3.1 | — | | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0967 | Red Hat | low | 2.2 | — | | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0966 | Red Hat | medium | 6.5 | — | | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-0965 | Red Hat | low | 3.3 | — | | No description is available for this CVE. | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2025-14821 | Red Hat | low | 7.8 | — | | A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security down… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-25506 | Red Hat | high | 7.7 | 0.0%
| ✓ Fix | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17,… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-26007 | Red Hat | high | 7.4 | 0.0%
| ✓ Fix | cryptography is a package designed to expose cryptographic primitives and recipes to Python develope… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-26013 | Red Hat | low | 3.7 | 0.0%
| | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the Chat… | Feb 10, 2026 | Feb 10, 2026 |
| | CVE-2026-2436 | Red Hat | medium | 6.5 | — | | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-69873 | Red Hat | high | 7.5 | 0.1%
| | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Serv… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-69872 | Red Hat | high | 7.6 | 0.1%
| ✓ Fix | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attac… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26158 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the in… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26157 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26079 | Red Hat | medium | 4.7 | 0.1%
| | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection,… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2369 | Red Hat | medium | 6.5 | — | | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2366 | Red Hat | low | 3.1 | 0.0%
| | No description is available for this CVE. | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-1837 | Red Hat | high | 8.8 | 0.0%
| | A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2025-12474 | Red Hat | low | 3.1 | 0.0%
| | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but alloc… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2020-37178 | Red Hat | high | 7.5 | 0.0%
| | KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help sys… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-25990 | Red Hat | high | 7.3 | 0.0%
| ✓ Fix | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be trigg… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26014 | Red Hat | medium | 5.9 | 0.1%
| | Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 thr… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26019 | Red Hat | medium | 4.1 | 0.0%
| | LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoa… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-26012 | Red Hat | medium | 6.5 | 0.0%
| | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-1669 | Red Hat | high | 6.5 | 0.0%
| | Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 throug… | Feb 11, 2026 | Feb 11, 2026 |
| | CVE-2026-2391 | Red Hat | medium | 5.3 | 0.0%
| | ### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `c… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2327 | Red Hat | medium | 7.5 | 0.0%
| | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expressi… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-21722 | Grafana | medium | 5.3 | 0.0%
| | Public dashboards with annotations enabled did not limit their annotation timerange to the locked ti… | Feb 12, 2026 | Apr 24, 2026 |
| | CVE-2025-41117 | Grafana | medium | 6.8 | 0.0%
| | Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious… | Feb 12, 2026 | Apr 24, 2026 |
| | CVE-2026-2003 | Red Hat | medium | 4.3 | 0.0%
| ✓ Fix | Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2004 | Red Hat | high | 8.8 | 0.1%
| ✓ Fix | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function … | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2005 | Red Hat | high | 8.8 | 0.1%
| ✓ Fix | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code a… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2006 | Red Hat | high | 8.8 | 0.1%
| ✓ Fix | Missing validation of multibyte character length in PostgreSQL text manipulation allows a database u… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2007 | Red Hat | high | 8.2 | 0.1%
| | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a c… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-25949 | Red Hat | high | 7.5 | 0.0%
| | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerabili… | Feb 12, 2026 | Feb 12, 2026 |
| | CVE-2026-2441 | Red Hat | high | 8.8 | 0.1%
| ⚠ KEV | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute a… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-23111 | Red Hat | medium | 7.0 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix invert… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-23112 | Red Hat | medium | 7.6 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: add bounds checks in … | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-2443 | Red Hat | low | 5.3 | 0.1%
| | A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2025-33042 | Red Hat | medium | 5.6 | 0.0%
| | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-26269 | Red Hat | low | 7.5 | 0.0%
| | Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerab… | Feb 13, 2026 | Feb 13, 2026 |
| | CVE-2026-23179 | Red Hat | medium | 6.5 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fixup hang in nvmet_t… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23156 | Red Hat | medium | 7.3 | 0.0%
| ✓ Fix | In the Linux kernel, the following vulnerability has been resolved:
efivarfs: fix error propagation … | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2025-71220 | Red Hat | low | 3.3 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
smb/server: call ksmbd_session_r… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23186 | Red Hat | medium | 5.5 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
hwmon: (acpi_power_meter) Fix de… | Feb 14, 2026 | Feb 14, 2026 |
| | CVE-2026-23153 | Red Hat | low | 5.5 | 0.0%
| | In the Linux kernel, the following vulnerability has been resolved:
firewire: core: fix race conditi… | Feb 14, 2026 | Feb 14, 2026 |