| | CVE-2026-46230 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's `drm/amdgpu/vcn3` component. This vulnerability, an Out-of-Bo… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46181 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in the Linux kernel's RDMA/mlx4 component. This vulnerability arises from the incor… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46111 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth subsystem. The `create_big_complete` function, when… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46206 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's `batman-adv` module, specifically in the `tp_meter` component… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46118 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's `pseries/papr-hvpipe` component. A local user could trigger a… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46207 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's `vsock/virtio` component. When processing non-linear data buf… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46159 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the btrfs filesystem within the Linux kernel. A Time-of-check to time-of-use (TO… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46146 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) usb-audio subsystem.… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46193 | Red Hat | medium | 7.0 | 0.0%
| | A flaw was found in the Linux kernel's xfrm: ah component, which handles network security protocols.… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46148 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's microchip-core-qspi driver. When multiple devices are connect… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46116 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in the Linux kernel's `xfrm` (IPSec framework) subsystem. This vulnerability, a use… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46157 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) Pulse Code Modulatio… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46187 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's Redpine Signals (RSI) Wi-Fi driver. A race condition, which o… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46154 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel, specifically within the `sched_ext` component. This vulnerabil… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-46190 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Memory Technology Device (MTD) SPI-NOR debugfs component. An … | May 28, 2026 | May 28, 2026 |
| | CVE-2026-32996 | Veeam | high | 7.3 | 0.0%
| | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. | May 28, 2026 | May 29, 2026 |
| | CVE-2026-32997 | Veeam | high | 8.6 | 0.0%
| | A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary… | May 28, 2026 | May 29, 2026 |
| | CVE-2026-32998 | Veeam | critical | 9.4 | 0.3%
| | This vulnerability in Veeam Service Provider Console allows for remote code execution. | May 28, 2026 | May 29, 2026 |
| | CVE-2025-48977 | Apache | medium | 6.5 | 0.0%
| | Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can r… | May 28, 2026 | May 29, 2026 |
| | CVE-2026-40914 | Apache | medium | 4.3 | 0.6%
| | A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with securi… | May 28, 2026 | Jun 15, 2026 |
| | CVE-2026-41565 | Red Hat | high | 9.8 | — | | A flaw was found in perl-CryptX. A stack buffer overflow vulnerability exists in the AEAD (Authentic… | May 28, 2026 | May 28, 2026 |
| | CVE-2026-10028 | Red Hat | low | 4.3 | — | | A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting … | May 28, 2026 | May 28, 2026 |
| | CVE-2026-10101 | Red Hat | medium | 6.3 | 0.0%
| | ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions… | May 29, 2026 | May 29, 2026 |
| | CVE-2026-35563 | Apache | high | 8.5 | 0.2%
| | It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-45192 | Apache | medium | 6.5 | 0.4%
| | A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed a… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-40861 | Apache | medium | 6.5 | 0.7%
| | A Dag author could either (a) create a symlink under their task's log directory pointing to an arbit… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-40961 | Apache | high | 7.2 | 0.6%
| | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that b… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-40963 | Apache | low | 3.1 | 0.5%
| | The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-41014 | Apache | medium | 4.3 | 0.4%
| | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not p… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-41017 | Apache | medium | 5.9 | 0.3%
| | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deploy… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-41084 | Apache | high | 7.5 | 0.5%
| | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-42252 | Apache | critical | 9.1 | 0.4%
| | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when tr… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-42253 | Apache | medium | 6.1 | 1.1%
| | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-42358 | Apache | medium | 6.5 | 0.3%
| | A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-42359 | Apache | high | 8.8 | 0.5%
| | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authentic… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-42360 | Apache | medium | 6.5 | 0.3%
| | A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g.… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-42588 | Apache | high | 8.1 | 0.5%
| | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-44825 | Apache | high | 8.1 | 0.5%
| | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr v… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-45360 | Apache | high | 7.3 | 0.7%
| | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_r… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-45426 | Apache | low | 3.1 | 0.3%
| | Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-45505 | Apache | high | 8.8 | 0.6%
| | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-46605 | Apache | medium | 4.3 | 0.3%
| | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authent… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-46764 | Apache | medium | 4.3 | 0.4%
| | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-48726 | Apache | medium | 6.5 | 0.4%
| | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-48827 | Apache | high | 7.1 | 0.5%
| | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-49157 | Apache | high | 8.8 | 0.4%
| | Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ:… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-49267 | Apache | medium | 5.9 | 0.2%
| | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STA… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-49270 | Apache | medium | 5.9 | 0.3%
| | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A… | Jun 1, 2026 | Jul 22, 2026 |
| | CVE-2026-49298 | Apache | high | 8.8 | 0.5%
| | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate a… | Jun 1, 2026 | Jul 21, 2026 |
| | CVE-2026-49361 | Apache | high | 7.5 | 0.6%
| | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.M… | Jun 1, 2026 | Jul 22, 2026 |