| | CVE-2026-33857 | Red Hat | medium | 7.5 | 0.2%
| ✓ Fix | A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) m… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-6266 | Red Hat | high | 8.3 | — | ✓ Fix | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatical… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-33523 | Red Hat | medium | 6.5 | 0.3%
| ✓ Fix | A flaw was found in httpd. When processing responses from an untrusted or compromised backend server… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-33007 | Red Hat | medium | 5.3 | 0.6%
| ✓ Fix | A flaw was found in the mod_authn_socache module of httpd. This vulnerability allows an unauthentica… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-33006 | Red Hat | medium | 4.8 | 0.2%
| ✓ Fix | A flaw was found in the mod_auth_digest module of httpd. A remote unauthenticated attacker can bypas… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-29169 | Red Hat | low | 7.5 | 0.6%
| ✓ Fix | A flaw was found in the mod_dav_lock module of httpd. This vulnerability allows a remote unauthentic… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-23918 | Apache | high | 8.8 | 45.8%
| | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This iss… | May 4, 2026 | Jul 15, 2026 |
| | CVE-2026-40563 | Apache | high | 8.1 | 0.1%
| | Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas… | May 4, 2026 | May 6, 2026 |
| | CVE-2026-24118 | Red Hat | high | 9.1 | 0.2%
| | A flaw was found in vm2, an open-source sandbox for Node.js. This sandbox breakout vulnerability all… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-24120 | Red Hat | high | 9.1 | 0.1%
| | A flaw was found in vm2, an open-source sandbox for Node.js. This vulnerability allows a remote atta… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-24781 | Red Hat | high | 8.1 | 0.2%
| | A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. This vulnerability… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-26332 | Red Hat | high | 9.1 | 0.1%
| | A flaw was found in vm2, an open-source sandbox for Node.js. This vulnerability allows a remote atta… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-26956 | Red Hat | high | 9.8 | 0.1%
| | A flaw was found in vm2, an open-source sandbox for Node.js. An attacker can exploit this vulnerabil… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-40682 | Apache | critical | 9.1 | 0.5%
| | XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersis… | May 4, 2026 | Sep 2, 2026 |
| | CVE-2026-42027 | Apache | critical | 9.8 | 0.7%
| | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Aff… | May 4, 2026 | Sep 9, 2026 |
| | CVE-2026-42440 | Apache | high | 7.5 | 0.6%
| | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Version… | May 4, 2026 | Jul 30, 2026 |
| | CVE-2026-42809 | Apache | critical | 9.9 | 0.1%
| | Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation… | May 4, 2026 | May 12, 2026 |
| | CVE-2026-42810 | Apache | critical | 9.9 | 0.1%
| | Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds tem… | May 4, 2026 | May 12, 2026 |
| | CVE-2026-42811 | Apache | critical | 9.9 | 0.1%
| | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for o… | May 4, 2026 | May 12, 2026 |
| | CVE-2026-42812 | Apache | critical | 9.9 | 0.1%
| | In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files … | May 4, 2026 | May 12, 2026 |
| | CVE-2026-29004 | Red Hat | high | 8.8 | 0.0%
| | A flaw was found in BusyBox. A heap buffer overflow vulnerability exists in the Dynamic Host Configu… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-43964 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically a… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-42151 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in Prometheus, an open-source monitoring system. The `client_secret` field within t… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-42154 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in Prometheus. An unauthenticated attacker can exploit the remote read endpoint (`/… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-6321 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | A flaw was found in fast-uri. A remote attacker could exploit this vulnerability by providing a spec… | May 4, 2026 | May 4, 2026 |
| | CVE-2026-7957 | Red Hat | medium | 6.5 | 0.1%
| | An out of bounds write flaw was found in the Media component of the Chromium browser.
Upstream bug(s… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7931 | Red Hat | medium | 6.5 | 0.1%
| | An insufficient validation of untrusted input flaw was found in the iOS component of the Chromium br… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7897 | Red Hat | high | 9.6 | 0.1%
| | An use after free flaw was found in the Mobile component of the Chromium browser.
Upstream bug(s):
h… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7960 | Red Hat | medium | 2.6 | 0.0%
| | A race flaw was found in the Speech component of the Chromium browser.
Upstream bug(s):
https://code… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7927 | Red Hat | high | 8.8 | 0.1%
| | A type confusion flaw was found in the Runtime component of the Chromium browser.
Upstream bug(s):
h… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7981 | Red Hat | medium | 6.5 | 0.0%
| | An out of bounds read flaw was found in the Codecs component of the Chromium browser.
Upstream bug(s… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7943 | Red Hat | medium | 9.0 | 0.0%
| | An insufficient validation of untrusted input flaw was found in the ANGLE component of the Chromium … | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7950 | Red Hat | medium | 8.8 | 0.0%
| | An out of bounds read and write flaw was found in the GFX component of the Chromium browser.
Upstrea… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7988 | Red Hat | medium | 9.6 | 0.1%
| | A type confusion flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
ht… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7938 | Red Hat | medium | 9.6 | 0.1%
| | An use after free flaw was found in the CSS component of the Chromium browser.
Upstream bug(s):
http… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7980 | Red Hat | medium | 8.8 | 0.1%
| | An use after free flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7912 | Red Hat | high | 8.0 | 0.0%
| | An integer overflow flaw was found in the GPU component of the Chromium browser.
Upstream bug(s):
ht… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-8019 | Red Hat | low | 4.3 | 0.1%
| | An insufficient policy enforcement flaw was found in the WebApp component of the Chromium browser.
U… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-8002 | Red Hat | low | 8.8 | 0.1%
| | An use after free flaw was found in the Audio component of the Chromium browser.
Upstream bug(s):
ht… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7964 | Red Hat | medium | 8.2 | 0.0%
| | An insufficient validation of untrusted input flaw was found in the FileSystem component of the Chro… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-8014 | Red Hat | low | 6.5 | 0.0%
| | An inappropriate implementation flaw was found in the Preload component of the Chromium browser.
Ups… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7917 | Red Hat | high | 9.0 | 0.1%
| | An use after free flaw was found in the Fullscreen component of the Chromium browser.
Upstream bug(s… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7978 | Red Hat | medium | 10.0 | 0.1%
| | An inappropriate implementation flaw was found in the Companion component of the Chromium browser.
U… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7904 | Red Hat | high | 6.5 | 0.0%
| | An out of bounds read flaw was found in the Fonts component of the Chromium browser.
Upstream bug(s)… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7940 | Red Hat | medium | 6.7 | 0.0%
| | An use after free flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-8001 | Red Hat | low | 8.2 | 0.1%
| | An use after free flaw was found in the Printing component of the Chromium browser.
Upstream bug(s):… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7939 | Red Hat | medium | 8.1 | 0.0%
| | An inappropriate implementation flaw was found in the SanitizerAPI component of the Chromium browser… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7922 | Red Hat | high | 9.6 | 0.1%
| | An use after free flaw was found in the ServiceWorker component of the Chromium browser.
Upstream bu… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-8018 | Red Hat | low | 10.0 | 0.1%
| | An insufficient policy enforcement flaw was found in the DevTools component of the Chromium browser.… | May 5, 2026 | May 5, 2026 |
| | CVE-2026-7935 | Red Hat | medium | 4.3 | 0.1%
| | An inappropriate implementation flaw was found in the Speech component of the Chromium browser.
Upst… | May 5, 2026 | May 5, 2026 |