| | CVE-2026-40612 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in jq, a command line JSON processor. The `jv_contains` function does not have a de… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-41256 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in jq, a command line JSON processor. Top-level jq programs loaded from a file usin… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-43894 | Red Hat | medium | 6.2 | 0.0%
| | A flaw was found in jq, a tool used for processing JSON data from the command line. A remote attacke… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-44777 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in jq, a command line JSON processor. The module loader fails to perform cycle dete… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-43895 | Red Hat | medium | 4.4 | 0.0%
| | A flaw was found in jq, a command line JSON processor. Embedded NUL bytes in import paths are trunca… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-43896 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in jq, a command line JSON processor. The `jv_object_merge_recursive` function, rea… | May 11, 2026 | May 11, 2026 |
| | CVE-2026-42050 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in ImageMagick. A user opening a specially crafted MIFF (Magick Image File Format) … | May 11, 2026 | May 11, 2026 |
| | CVE-2026-6402 | Red Hat | medium | 5.3 | 0.0%
| | A flaw was found in webpack-dev-server. When the development server operates over plain HTTP, a remo… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-41712 | VMware | high | 7.5 | 0.0%
| | Spring AI's chat memory component contained a problematic default that, when not explicitly overridd… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-41713 | VMware | high | 8.2 | 0.0%
| | A malicious user could craft input that is stored in conversation memory and later interpreted by th… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8388 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed … | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8389 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issu… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8390 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issu… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8391 | Red Hat | high | 7.5 | 0.1%
| ✓ Fix | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Fir… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-33603 | Red Hat | medium | 6.8 | 0.0%
| | A flaw was found in Dovecot. An attacker, positioned as a Man-in-the-Middle (MITM) between Dovecot a… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-40016 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in Dovecot. A remote or local attacker could upload a malicious Sieve script throug… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-40020 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in dovecot. A remote attacker can exploit the Internet Message Access Protocol (IMA… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8368 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in LWP::UserAgent, a component of perl-libwww-perl. This vulnerability allows a rem… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-8401 | Red Hat | high | 7.5 | 0.1%
| ✓ Fix | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Fir… | May 12, 2026 | May 12, 2026 |
| | CVE-2026-43515 | Apache | medium | — | 0.1%
| | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the … | May 12, 2026 | Jun 4, 2026 |
| | CVE-2026-5089 | Red Hat | medium | 4.0 | 0.0%
| | A flaw was found in perl-YAML-Syck. The base60 (sexagesimal) parsing code in perl_syck.h contains a … | May 12, 2026 | May 12, 2026 |
| | CVE-2026-41284 | Apache | high | 7.5 | 0.0%
| | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue aff… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-41293 | Apache | critical | 9.8 | 0.2%
| | Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-42498 | Apache | high | 7.3 | 0.1%
| | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerabi… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-43512 | Apache | critical | 9.8 | 0.1%
| | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
T… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-43513 | Apache | high | 7.5 | 0.1%
| | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue af… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-43514 | Apache | low | 3.7 | 0.0%
| | Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.
This issue … | May 12, 2026 | May 14, 2026 |
| | CVE-2026-20794 | VMware | critical | 9.3 | — | | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-25088 | Fortinet | medium | 5.1 | 0.3%
| | An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit… | May 12, 2026 | Jul 8, 2026 |
| | CVE-2025-53844 | Fortinet | high | 8.3 | 0.6%
| | A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7… | May 12, 2026 | Aug 11, 2026 |
| | CVE-2026-25690 | Fortinet | medium | 4.0 | 0.2%
| | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability … | May 12, 2026 | Jul 8, 2026 |
| | CVE-2025-53681 | Fortinet | medium | 6.3 | 0.4%
| | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerabili… | May 12, 2026 | Jul 8, 2026 |
| | CVE-2025-53870 | Fortinet | medium | 6.5 | 0.6%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | May 12, 2026 | Jul 8, 2026 |
| | CVE-2026-21530 | Microsoft | medium | 6.7 | — | | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33834 | Microsoft | high | 7.8 | — | | Improper access control in Windows Event Logging Service allows an authorized attacker to elevate pr… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33839 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33840 | Microsoft | high | 7.8 | — | | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33841 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34329 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34330 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate pri… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34331 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34333 | Microsoft | high | 7.8 | — | | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34342 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34343 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34344 | Microsoft | high | 7.8 | — | | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34345 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34347 | Microsoft | high | 7.0 | — | | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34350 | Microsoft | medium | 6.5 | — | | Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-34351 | Microsoft | high | 7.8 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35415 | Microsoft | high | 7.8 | — | | Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to… | May 12, 2026 | May 13, 2026 |