| | CVE-2026-43285 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel. An inconsistent lock state within the `mm/slab` subsystem, spe… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43293 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's wave5 media driver. During the removal of the wave5 module in… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43345 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's ipa driver. This vulnerability, affecting IPA version 5.0 and… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43342 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's USB gadget RNDIS (Remote Network Driver Interface Specificati… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43309 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's md raid and device-mapper (dm-raid) components. When a local … | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43453 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's netfilter component, specifically within the `nft_set_pipapo`… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-42203 | Red Hat | high | 8.8 | 0.1%
| | A flaw was found in LiteLLM, an AI Gateway. An authenticated user could exploit this by sending a cr… | May 8, 2026 | May 8, 2026 |
| | CVE-2013-10075 | Apache | medium | — | — | | Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apac… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-43284 | Fortinet | high | 8.8 | 93.2%
| | In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decry… | May 8, 2026 | Jul 1, 2026 |
| | CVE-2026-41493 | Red Hat | medium | 5.3 | 0.1%
| | A flaw was found in YARD, a Ruby Documentation tool. When using `yard server` to serve documentation… | May 8, 2026 | May 8, 2026 |
| | CVE-2025-66170 | Apache | medium | 6.5 | 0.0%
| | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. … | May 8, 2026 | May 11, 2026 |
| | CVE-2025-66171 | Apache | medium | 6.5 | 0.0%
| | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone … | May 8, 2026 | May 12, 2026 |
| | CVE-2025-66172 | Apache | high | 8.1 | 0.0%
| | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone … | May 8, 2026 | May 12, 2026 |
| | CVE-2025-66467 | Apache | high | 8.0 | 0.0%
| | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access … | May 8, 2026 | May 11, 2026 |
| | CVE-2025-69233 | Apache | medium | 6.5 | 0.0%
| | Due to multiple time-of-check time-of-use race conditions in the resource count check and increment … | May 8, 2026 | May 9, 2026 |
| | CVE-2026-25077 | Apache | high | 8.8 | 0.0%
| | Account users are allowed by default to register templates to be downloaded directly to the primary … | May 8, 2026 | May 10, 2026 |
| | CVE-2026-25199 | Apache | critical | 9.1 | 0.0%
| | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to oth… | May 8, 2026 | May 9, 2026 |
| | CVE-2026-41506 | Red Hat | medium | 6.5 | 0.1%
| ✓ Fix | A flaw was found in go-git, an extensible Git implementation library for Go. This vulnerability allo… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-39816 | Apache | high | 8.8 | 0.0%
| | The optional extension component TinkerpopClientService is missing the Restricted annotation with th… | May 8, 2026 | May 9, 2026 |
| | CVE-2026-41889 | Red Hat | medium | 5.9 | 0.0%
| ✓ Fix | A flaw was found in pgx, a PostgreSQL driver and toolkit for Go. This SQL injection vulnerability ca… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-6659 | Red Hat | medium | 6.1 | 0.0%
| | Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.
The buil… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-45130 | Red Hat | medium | 6.6 | 0.0%
| | A flaw was found in Vim, an open-source command-line text editor. A heap buffer overflow exists in t… | May 8, 2026 | May 8, 2026 |
| | CVE-2026-5172 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-4893 | Red Hat | medium | 6.5 | 0.0%
| ✓ Fix | An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks v… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-4892 | Red Hat | high | 8.8 | 0.0%
| ✓ Fix | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local … | May 9, 2026 | May 9, 2026 |
| | CVE-2026-4891 | Red Hat | high | 7.5 | 0.1%
| ✓ Fix | A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote atta… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-4890 | Red Hat | high | 7.5 | 0.2%
| ✓ Fix | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers … | May 9, 2026 | May 9, 2026 |
| | CVE-2026-2291 | Red Hat | medium | 6.5 | 0.1%
| ✓ Fix | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-41705 | VMware | high | 8.6 | 0.4%
| | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injec… | May 9, 2026 | Jul 24, 2026 |
| | CVE-2026-42183 | Red Hat | medium | 5.3 | 0.1%
| | A flaw was found in Argo Workflows. This flaw, a nil pointer dereference in the `rbacAuthorization()… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42295 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in Argo Workflows, an open source container-native workflow engine for orchestratin… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42309 | Red Hat | medium | 5.1 | 0.0%
| ✓ Fix | A flaw was found in Pillow, a Python imaging library. A malicious actor could exploit this vulnerabi… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42308 | Red Hat | medium | 6.2 | 0.0%
| | A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceed… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42310 | Red Hat | medium | 4.0 | 0.0%
| ✓ Fix | Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can sup… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42245 | Red Hat | medium | 6.5 | 0.1%
| | A flaw was found in Net::IMAP, a Ruby library implementing the Internet Message Access Protocol (IMA… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42256 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in Net::IMAP, a Ruby library for Internet Message Access Protocol (IMAP) client fun… | May 9, 2026 | May 9, 2026 |
| | CVE-2026-42257 | Red Hat | medium | 6.1 | 0.0%
| | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to … | May 9, 2026 | May 9, 2026 |
| | CVE-2026-6735 | Red Hat | medium | 5.4 | 0.0%
| ✓ Fix | A flaw was found in PHP, specifically within the PHP-FPM status page. Due to improper sanitation of … | May 10, 2026 | May 10, 2026 |
| | CVE-2026-7568 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in PHP. The metaphone() function in ext/standard/metaphone.c uses a signed int vari… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-7262 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in PHP. When a PHP SOAP server has a typemap configured, the apache:Map decoding pr… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-7258 | Red Hat | medium | 5.9 | 0.0%
| ✓ Fix | A flaw was found in PHP. Some functions, including `urldecode()`, incorrectly pass signed characters… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-6104 | Red Hat | high | 8.2 | 0.0%
| | A flaw was found in PHP. When an encoding name containing an embedded NUL byte is passed to `mb_conv… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-45186 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pa… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-45190 | Red Hat | medium | 6.5 | 0.1%
| | A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerabilit… | May 10, 2026 | May 10, 2026 |
| | CVE-2026-8261 | Red Hat | medium | 6.1 | 0.0%
| | A flaw was found in Squirrel. A local attacker could exploit a heap-based buffer overflow vulnerabil… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-43500 | Fortinet | high | 7.8 | 92.6%
| | In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPON… | May 11, 2026 | Jun 30, 2026 |
| | CVE-2026-41018 | Apache | medium | 6.5 | 0.0%
| | The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for e… | May 11, 2026 | May 13, 2026 |
| | CVE-2026-43826 | Apache | medium | 6.5 | 0.0%
| | The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for exam… | May 11, 2026 | May 13, 2026 |
| | CVE-2026-4802 | Red Hat | high | 8.0 | — | | A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary comman… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-41257 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in jq, a command line JSON processor. The memory allocation size is calculated usin… | May 11, 2026 | May 11, 2026 |