| | CVE-2026-43496 | Red Hat | low | 5.5 | — | | A flaw was found in the Linux kernel's networking scheduler component. This vulnerability occurs whe… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43497 | Red Hat | medium | — | — | | A flaw was found in the Linux kernel's udlfb driver. This use-after-free vulnerability occurs becaus… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43501 | Red Hat | high | 7.0 | — | | A flaw was found in the Linux kernel. A local attacker can exploit an out-of-bounds write vulnerabil… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43502 | Red Hat | medium | 5.5 | — | | A flaw was found in the Linux kernel, specifically within the Remote Direct Memory Access (RDMA) sub… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43498 | Red Hat | medium | — | — | | A flaw was found in the Linux kernel's accel/ivpu module. This vulnerability allows for the re-expor… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43499 | Red Hat | medium | — | — | | A flaw was found in the Linux kernel. When the kernel's real-time mutex (rtmutex) component performs… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43495 | Red Hat | medium | — | — | | A flaw was found in the Linux kernel, specifically within the net: wwan: t7xx module. A malicious mo… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-43494 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in the Linux kernel, specifically within the `net/rds` module. When a zerocopy page… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-2734 | Red Hat | medium | 6.5 | 0.0%
| | A flaw was found in mlflow. An authenticated user could exploit a lack of proper authorization check… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-45760 | Apache | medium | — | — | | (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through Use… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-3593 | Red Hat | high | 7.4 | 0.0%
| | A flaw was found in the BIND (Berkeley Internet Name Domain) DNS-over-HTTPS implementation. A remote… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-5947 | Red Hat | high | 7.5 | 0.0%
| | A flaw was found in BIND. A remote attacker could exploit a race condition during SIG(0) signature v… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-3039 | Red Hat | high | 7.5 | 0.1%
| ✓ Fix | A flaw was found in BIND. A remote attacker can exploit this vulnerability by sending maliciously-co… | May 21, 2026 | May 21, 2026 |
| | CVE-2026-5946 | Red Hat | high | 7.5 | 0.0%
| ✓ Fix | No description is available for this CVE. | May 21, 2026 | May 21, 2026 |
| | CVE-2026-48207 | Apache | critical | 9.8 | 0.6%
| | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docu… | May 21, 2026 | Jul 23, 2026 |
| | CVE-2026-44417 | Apache | high | 7.5 | 0.6%
| | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-44618 | Apache | medium | 5.3 | 0.3%
| | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-44930 | Apache | critical | 9.8 | 0.7%
| | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-9277 | Red Hat | high | 8.1 | 0.1%
| | A flaw was found in the shell-quote component. The quote() function did not properly validate object… | May 22, 2026 | May 22, 2026 |
| | CVE-2026-9256 | F5 | high | 8.1 | 10.0%
| | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vu… | May 22, 2026 | Aug 25, 2026 |
| | CVE-2026-45659 | Microsoft | high | 8.8 | 9.1%
| ⚠ KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 22, 2026 | Aug 11, 2026 |
| | CVE-2026-23652 | Microsoft | critical | 10.0 | 0.6%
| | Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-23663 | Microsoft | high | 7.5 | 0.6%
| | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privilege… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-26147 | Microsoft | high | 7.7 | 0.6%
| | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose informa… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-33843 | Microsoft | critical | 9.1 | 0.5%
| | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C all… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-35430 | Microsoft | high | 8.8 | 0.4%
| | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allow… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-40411 | Microsoft | critical | 9.9 | 0.5%
| | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-40412 | Microsoft | critical | 10.0 | 0.5%
| | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attac… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-41090 | Microsoft | critical | 9.3 | 0.4%
| | Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-41104 | Microsoft | critical | 10.0 | 0.9%
| | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacke… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-42827 | Microsoft | medium | 6.5 | 0.5%
| | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-42901 | Microsoft | critical | 10.0 | 0.3%
| | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-47280 | Microsoft | critical | 10.0 | 0.5%
| | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate p… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-43503 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in the Linux kernel's networking (skbuff) component. When skb_try_coalesce() attach… | May 23, 2026 | May 23, 2026 |
| | CVE-2026-9298 | Red Hat | medium | 6.3 | 0.0%
| | A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an u… | May 23, 2026 | May 23, 2026 |
| | CVE-2026-2651 | Red Hat | critical | 9.0 | 0.1%
| | A flaw was found in MLflow when the `--serve-artifacts` mode is enabled. A remote attacker can explo… | May 25, 2026 | May 25, 2026 |
| | CVE-2026-41863 | VMware | medium | 6.5 | 0.4%
| | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.res… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-45249 | Apache | medium | 6.1 | 0.8%
| | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rend… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-45361 | Apache | high | 8.1 | 0.6%
| | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defau… | May 25, 2026 | Jul 21, 2026 |
| | CVE-2026-46745 | Apache | medium | 5.3 | 0.6%
| | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-42782 | Apache | high | 7.2 | 0.7%
| | Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with a… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-42797 | Apache | medium | 4.9 | 0.4%
| | Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administ… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-43827 | Apache | medium | 6.5 | 0.4%
| | Default configurations of Apache Shiro have a session fixation vulnerability.
This issue affects Ap… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-43828 | Apache | medium | 6.5 | 0.3%
| | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-44598 | Apache | medium | 5.4 | 0.4%
| | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-48589 | Apache | medium | 5.4 | 0.4%
| | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-45835 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-45834 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-45836 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP subsystem. This vulnerability, a null-pointer… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-4408 | Red Hat | high | 9.0 | 0.2%
| | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers an… | May 26, 2026 | May 26, 2026 |