| | CVE-2026-23818 | HPE | high | 8.8 | — | | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Pr… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-32144 | Red Hat | high | 7.4 | — | | A flaw was found in Erlang OTP public_key. This improper certificate validation vulnerability allows… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-28808 | Red Hat | high | 7.4 | — | | A flaw was found in Erlang OTP (inets modules). A remote unauthenticated attacker could exploit an i… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-24450 | Red Hat | medium | 7.5 | — | | A flaw was found in LibRaw. A remote attacker could exploit an integer overflow vulnerability by pro… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-24660 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw. A remote attacker could exploit a heap-based buffer overflow vulnerabili… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-20889 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw, a library used for processing raw image files. This vulnerability, a hea… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-21413 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw. A heap-based buffer overflow vulnerability exists in the `lossless_jpeg_… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-20911 | Red Hat | high | 7.5 | — | | A flaw was found in LibRaw. A remote attacker can exploit a heap-based buffer overflow vulnerability… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4740 | Red Hat | high | 8.2 | — | | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluste… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-3902 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit an ambiguous mapping of header variants (w… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4277 | Red Hat | medium | 5.4 | — | | A flaw was found in Django. This vulnerability allows an attacker to bypass permission validation by… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4292 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. Admin changelist forms utilizing `ModelAdmin.list_editable` were suscept… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33033 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit this vulnerability by submitting specially… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-33034 | Red Hat | medium | 5.3 | — | | A flaw was found in Django. A remote attacker can exploit this vulnerability by sending ASGI (Asynch… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-4631 | Red Hat | critical | 9.8 | — | | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface t… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-27314 | Apache | high | 8.8 | 0.0%
| | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator all… | Apr 7, 2026 | Apr 15, 2026 |
| | CVE-2026-27315 | Apache | medium | 5.5 | 0.0%
| | Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, … | Apr 7, 2026 | Apr 15, 2026 |
| | CVE-2026-32588 | Apache | medium | 6.5 | 0.0%
| | Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise quer… | Apr 7, 2026 | Apr 15, 2026 |
| | CVE-2026-39363 | Red Hat | high | 7.5 | — | | A flaw was found in Vite, a frontend tooling framework. A remote attacker can exploit this vulnerabi… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39364 | Red Hat | high | 7.5 | — | | A flaw was found in Vite, a frontend tooling framework for JavaScript. On the Vite development serve… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39365 | Red Hat | medium | 5.3 | — | | A flaw was found in Vite. The development server's handling of `.map` requests contains a path trave… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-39373 | Red Hat | high | 7.5 | — | | A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and… | Apr 7, 2026 | Apr 7, 2026 |
| | CVE-2026-31411 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's Asynchronous Transfer Mode (ATM) networking component. A loca… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32591 | Red Hat | high | 5.2 | — | | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administr… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32590 | Red Hat | medium | 7.1 | — | | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload p… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32589 | Red Hat | high | 7.1 | — | | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push a… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-27144 | Red Hat | medium | 8.1 | 0.0%
| | A flaw was found in the cmd/compile package in the Go standard library. A no-op interface conversion… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32289 | Red Hat | medium | 5.4 | 0.0%
| | A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-27143 | Red Hat | medium | 8.1 | 0.0%
| | A flaw was found in the cmd/compile package in the Go standard library. The compiler fails to correc… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32288 | Red Hat | medium | 4.3 | 0.0%
| | A flaw was found in Go's `archive/tar` package. A remote attacker could exploit this vulnerability b… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-32281 | Red Hat | medium | 5.9 | 0.0%
| | A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-58713 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57854 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. T… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57853 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems fro… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57851 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57847 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This … | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-39865 | Red Hat | medium | 5.9 | — | | A flaw was found in Axios, a promise-based HTTP client. A malicious server can exploit a state corru… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-33753 | Red Hat | medium | 6.2 | — | | A flaw was found in rfc3161-client, a Python library implementing the Time-Stamp Protocol (TSP). Thi… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-2377 | Red Hat | high | 6.5 | — | | A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by provi… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-14243 | Red Hat | medium | 5.3 | — | | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, rem… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-39881 | Red Hat | medium | 5.0 | — | | A flaw was found in Vim. A command injection vulnerability in Vim's NetBeans interface allows a mali… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-62188 | Apache | high | 7.5 | 0.0%
| | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache Dolphin… | Apr 9, 2026 | Apr 17, 2026 |
| | CVE-2026-34538 | Apache | medium | 6.5 | 0.0%
| | Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to … | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2025-57735 | Apache | critical | 9.1 | 0.0%
| | When user logged out, the JWT token the user had authtenticated with was not invalidated, which coul… | Apr 9, 2026 | Apr 17, 2026 |
| | CVE-2026-34757 | Red Hat | medium | 4.4 | — | | A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files.… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-33005 | Apache | medium | 4.3 | 0.0%
| | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.
Any registered u… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-33266 | Apache | high | 7.5 | 0.0%
| | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie en… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-34020 | Apache | high | 7.5 | 0.0%
| | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The RE… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-34941 | Red Hat | medium | 5.3 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. When transcoding a UTF-16 string to the lat… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34942 | Red Hat | medium | 5.6 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. This vulnerability allows a malicious guest… | Apr 9, 2026 | Apr 9, 2026 |