| | CVE-2026-32281 | Red Hat | medium | 5.9 | 0.0%
| | A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-5795 | Red Hat | high | 7.4 | 0.0%
| ✓ Fix | A flaw was found in Eclipse Jetty. The `JASPIAuthenticator` class is responsible for handling authen… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-58713 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57854 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. T… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57853 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems fro… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57851 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-57847 | Red Hat | medium | 6.4 | — | | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This … | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-39865 | Red Hat | medium | 5.9 | — | | A flaw was found in Axios, a promise-based HTTP client. A malicious server can exploit a state corru… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-33753 | Red Hat | medium | 6.2 | — | | A flaw was found in rfc3161-client, a Python library implementing the Time-Stamp Protocol (TSP). Thi… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-2377 | Red Hat | high | 6.5 | — | | A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by provi… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2025-14243 | Red Hat | medium | 5.3 | — | | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, rem… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-20709 | Red Hat | medium | 6.6 | 0.0%
| | A flaw was found in some Intel Pentium Processor Silver Series, Intel Celeron Processor J Series, an… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-23869 | Red Hat | high | 7.5 | 0.8%
| | A flaw was found in react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-39881 | Red Hat | medium | 5.0 | — | | A flaw was found in Vim. A command injection vulnerability in Vim's NetBeans interface allows a mali… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-39892 | Red Hat | high | 7.3 | 0.0%
| ✓ Fix | cryptography is a package designed to expose cryptographic primitives and recipes to Python develope… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-5858 | Red Hat | high | 8.8 | 0.1%
| | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to e… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-5874 | Red Hat | high | 9.6 | 0.1%
| | Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who co… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-5894 | Red Hat | medium | 5.4 | 0.0%
| | Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacke… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-40024 | Red Hat | high | 7.9 | 0.0%
| | A flaw was found in The Sleuth Kit, specifically in the tsk_recover tool. An attacker can exploit th… | Apr 8, 2026 | Apr 8, 2026 |
| | CVE-2026-6862 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fai… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2025-62188 | Apache | high | 7.5 | 0.0%
| | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache Dolphin… | Apr 9, 2026 | Apr 17, 2026 |
| | CVE-2026-34538 | Apache | medium | 6.5 | 0.0%
| | Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to … | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2025-57735 | Apache | critical | 9.1 | 0.0%
| | When user logged out, the JWT token the user had authtenticated with was not invalidated, which coul… | Apr 9, 2026 | Apr 17, 2026 |
| | CVE-2026-4660 | Red Hat | high | 7.5 | 0.0%
| | HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during … | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2025-62718 | Red Hat | high | 7.0 | 0.1%
| ✓ Fix | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios … | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34757 | Red Hat | medium | 4.4 | — | | A flaw was found in libpng, a library used for handling PNG (Portable Network Graphics) image files.… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-40046 | Red Hat | medium | 5.4 | 0.1%
| | Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveM… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-33005 | Apache | medium | 4.3 | 0.0%
| | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.
Any registered u… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-33266 | Apache | high | 7.5 | 0.0%
| | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie en… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-34020 | Apache | high | 7.5 | 0.0%
| | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The RE… | Apr 9, 2026 | Apr 15, 2026 |
| | CVE-2026-39983 | Red Hat | high | 8.6 | 2.0%
| ✓ Fix | A flaw was found in basic-ftp, an FTP client for Node.js. A remote attacker can exploit this vulnera… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34941 | Red Hat | medium | 5.3 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. When transcoding a UTF-16 string to the lat… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34942 | Red Hat | medium | 5.6 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. This vulnerability allows a malicious guest… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34943 | Red Hat | medium | 5.0 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. A malicious guest can exploit an issue wher… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34944 | Red Hat | medium | 4.7 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. On x86-64 platforms with SSE3 disabled, Was… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34945 | Red Hat | medium | 5.6 | — | | A flaw was found in Wasmtime's Winch compiler. This vulnerability, present in versions from 25.0.0 t… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34946 | Red Hat | medium | 5.3 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly (Wasm) code. A malicious Wasm program, when … | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34971 | Red Hat | high | 8.5 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. On aarch64 systems, a miscompilation bug in… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34983 | Red Hat | low | 2.5 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. This vulnerability allows for a use-after-f… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34987 | Red Hat | medium | 8.5 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. When using its non-default Winch compiler b… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34988 | Red Hat | medium | 5.6 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. When Wasmtime's pooling allocator is config… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-35186 | Red Hat | medium | 6.9 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. The Winch compiler backend incorrectly hand… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-35195 | Red Hat | medium | 6.3 | — | | A flaw was found in Wasmtime, a runtime for WebAssembly. A malicious guest component can exploit an … | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-34734 | F5 | high | 7.8 | 0.2%
| | HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the … | Apr 9, 2026 | Jul 15, 2026 |
| | CVE-2026-39977 | Red Hat | medium | 6.3 | 0.0%
| | A flaw was found in flatpak-builder. A specially crafted manifest or source can bypass path restrict… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-24880 | Red Hat | low | 4.3 | 0.2%
| ✓ Fix | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-25854 | Red Hat | low | 4.3 | 0.0%
| ✓ Fix | Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-29129 | Red Hat | low | 6.5 | 0.0%
| | Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects … | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-29145 | Red Hat | medium | 5.9 | 0.0%
| ✓ Fix | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v… | Apr 9, 2026 | Apr 9, 2026 |
| | CVE-2026-29146 | Apache | medium | — | 6.3%
| | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This… | Apr 9, 2026 | Aug 17, 2026 |