| | CVE-2026-8968 | Red Hat | low | 3.4 | 0.1%
| ✓ Fix | A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issu… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-8970 | Red Hat | low | 3.4 | 0.0%
| ✓ Fix | A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issu… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-8974 | Red Hat | medium | 6.1 | 0.0%
| ✓ Fix | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-8975 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these … | May 19, 2026 | May 19, 2026 |
| | CVE-2026-47323 | Apache | critical | 9.8 | 1.4%
| | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knat… | May 19, 2026 | Jul 15, 2026 |
| | CVE-2026-8711 | F5 | high | 8.1 | 0.9%
| | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least o… | May 19, 2026 | Jul 23, 2026 |
| | CVE-2026-47356 | Tenable | high | 7.5 | 0.5%
| | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url… | May 19, 2026 | Jul 24, 2026 |
| | CVE-2026-47357 | Tenable | high | 7.5 | 0.5%
| | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url … | May 19, 2026 | Jul 24, 2026 |
| | CVE-2026-47358 | Tenable | high | 7.5 | 0.5%
| | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL re… | May 19, 2026 | Jul 24, 2026 |
| | CVE-2026-32738 | Red Hat | medium | 6.5 | — | | A flaw was found in libheif, a HEIF and AVIF file format decoder and encoder. A remote attacker coul… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-32739 | Red Hat | medium | 6.5 | — | | A flaw was found in libheif, a HEIF and AVIF file format decoder and encoder. A remote attacker coul… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-32740 | Red Hat | high | 8.8 | — | | A flaw was found in libheif, a library for decoding and encoding HEIF and AVIF image files. This hea… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-32814 | Red Hat | medium | 6.5 | — | | A flaw was found in libheif, a HEIF and AVIF file format decoder and encoder. When processing a spec… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-32741 | Red Hat | high | 7.1 | — | | A flaw was found in libheif, a library for decoding and encoding HEIF (High Efficiency Image File Fo… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-32882 | Red Hat | high | 7.1 | — | | A flaw was found in libheif, a library used for handling High Efficiency Image File Format (HEIF) an… | May 19, 2026 | May 19, 2026 |
| | CVE-2026-27173 | Apache | high | 8.7 | 0.2%
| | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read… | May 19, 2026 | Jul 24, 2026 |
| | CVE-2026-42526 | Apache | medium | 5.3 | 0.4%
| | In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-ama… | May 19, 2026 | Jul 24, 2026 |
| | CVE-2026-45585 | Microsoft | medium | 6.8 | 0.1%
| | Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &qu… | May 19, 2026 | May 21, 2026 |
| | CVE-2026-42923 | Red Hat | medium | 5.3 | 0.1%
| ✓ Fix | A flaw was found in Unbound's DNSSEC validator where the code path for consulting the negative cache… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-42960 | Red Hat | medium | 5.9 | 0.0%
| ✓ Fix | A flaw was found in Unbound's handling of DNS reply messages, complementing the earlier CVE-2025-114… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-43617 | Red Hat | medium | 4.2 | 0.0%
| | A flaw was found in rsync. When an rsync daemon is configured with "daemon chroot = /X" and uses hos… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-43619 | Red Hat | medium | 6.3 | 0.0%
| | A flaw was found in rsync. A local attacker with filesystem access on the daemon host can exploit a … | May 20, 2026 | May 20, 2026 |
| | CVE-2026-43620 | Red Hat | medium | 6.5 | 0.0%
| | Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-29518 | Red Hat | high | 7.8 | 0.0%
| | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-43618 | Red Hat | high | 8.1 | 0.1%
| | A flaw was found in rsync. An authenticated daemon peer can exploit an integer overflow vulnerabilit… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-42959 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in Unbound's DNSSEC validator when constructing chase-reply messages for validation… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-45232 | Red Hat | medium | 5.9 | 0.0%
| | A flaw was found in rsync. A network attacker can exploit an off-by-one out-of-bounds stack write vu… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-47783 | Red Hat | high | 8.1 | 0.1%
| | A flaw was found in memcached. A remote attacker can exploit a timing side channel during Simple Aut… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-47784 | Red Hat | medium | 5.9 | 0.1%
| | A flaw was found in memcached. This vulnerability involves a timing side channel during SASL (Simple… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-9064 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-44608 | Red Hat | medium | 5.9 | 0.1%
| ✓ Fix | A flaw was found in Unbound. When operating in a multi-threaded configuration with specific Response… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-42944 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in Unbound, a Domain Name System (DNS) resolver. A remote attacker could trigger a … | May 20, 2026 | May 20, 2026 |
| | CVE-2026-33278 | Red Hat | high | 8.1 | 0.4%
| | A flaw was discovered in Unbound’s DNSSEC validator can leave it using an invalid memory pointer aft… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-41091 | Microsoft | high | 7.8 | 8.4%
| ⚠ KEV | Improper link resolution before file access ('link following') in Microsoft Defender allows an autho… | May 20, 2026 | Jul 24, 2026 |
| | CVE-2026-42834 | Microsoft | high | 7.8 | 0.4%
| | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges … | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-45498 | Microsoft | medium | 4.0 | 63.1%
| ⚠ KEV | Microsoft Defender Denial of Service Vulnerability | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-45584 | Microsoft | high | 8.1 | 0.9%
| | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code ove… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-9087 | Red Hat | medium | 6.4 | — | | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId,
i… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-20171 | Cisco | medium | 6.8 | 0.5%
| | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nex… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-20199 | Cisco | medium | 4.7 | 0.4%
| | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow … | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-20206 | Cisco | medium | 6.3 | 0.4%
| | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowe… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-20223 | Cisco | critical | 10.0 | 0.8%
| | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could a… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-47099 | Red Hat | medium | 5.4 | 0.0%
| | TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() funct… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-20238 | Splunk | medium | 6.5 | 0.3%
| | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or '… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-20239 | Splunk | high | 7.5 | 0.5%
| | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-20240 | Splunk | medium | 6.5 | 0.4%
| | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform ve… | May 20, 2026 | Jul 23, 2026 |
| | CVE-2026-8631 | HPE | critical | 9.8 | 1.7%
| | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software… | May 20, 2026 | Aug 4, 2026 |
| | CVE-2026-8632 | HPE | high | 7.8 | 0.9%
| | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software… | May 20, 2026 | Aug 4, 2026 |
| | CVE-2026-9149 | Red Hat | medium | 6.5 | — | | MANUALLY_VERIFIED_REPORT
package: libsolv-0.7.33-2.el10
------
[Security] Heap Buffer Overflow in re… | May 20, 2026 | May 20, 2026 |
| | CVE-2026-9150 | Red Hat | medium | 6.5 | — | | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi… | May 20, 2026 | May 20, 2026 |