| | CVE-2026-46322 | Red Hat | medium | 5.5 | — | | A flaw was found in the Linux kernel's `tun` driver. This vulnerability occurs when the `build_skb()… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46320 | Red Hat | medium | 5.5 | — | | A flaw was found in the Linux kernel's tap driver. This vulnerability occurs in the `tap_get_user_xd… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46318 | Red Hat | low | 5.5 | — | | A flaw was found in the Linux kernel's hugetlbfs component. An issue in the `mmap_prepare` stage inc… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46316 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for ARM64, specifically wi… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46324 | Red Hat | medium | 7.0 | — | | No description is available for this CVE. | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46319 | Red Hat | high | 7.0 | — | | A flaw was found in the Linux kernel. A race condition in the `act_ct` module, specifically during t… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46321 | Red Hat | medium | 5.5 | — | | A flaw was found in the Linux kernel. A local attacker with access to the tun/tap device can exploit… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46317 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) for arm64 architectures. A… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-46315 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's `io_uring` subsystem, specifically within the `IORING_OP_WAIT… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-41006 | VMware | high | 7.5 | 0.3%
| | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JS… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41007 | VMware | high | 7.5 | 0.3%
| | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41838 | VMware | medium | 4.8 | 0.2%
| | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, w… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41839 | VMware | medium | 4.2 | 0.2%
| | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41840 | VMware | medium | 5.9 | 0.2%
| | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41841 | VMware | medium | 5.9 | 0.3%
| | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41842 | VMware | high | 7.5 | 0.4%
| | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41843 | VMware | medium | 5.9 | 0.3%
| | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41844 | VMware | medium | 4.2 | 0.1%
| | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41845 | VMware | high | 7.1 | 0.2%
| | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41846 | VMware | medium | 5.9 | 0.1%
| | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41847 | VMware | medium | 4.8 | 0.2%
| | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41848 | VMware | low | 3.7 | 0.3%
| | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attack… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41849 | VMware | high | 7.5 | 0.3%
| | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41850 | VMware | high | 7.5 | 0.4%
| | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerabl… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41851 | VMware | medium | 5.3 | 0.4%
| | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnera… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41852 | VMware | low | 3.7 | 0.2%
| | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41853 | VMware | medium | 5.3 | 0.2%
| | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41854 | VMware | medium | 4.2 | 0.1%
| | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41855 | VMware | high | 8.1 | 0.3%
| | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-52902 | Red Hat | medium | 4.7 | 0.0%
| | A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directiv… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-52903 | Red Hat | high | 8.8 | — | | A deserialization of untrusted data vulnerability was found in ManageIQ. The YamlLoadAliases module… | Jun 9, 2026 | Jun 9, 2026 |
| | CVE-2026-25688 | Apache | medium | 6.1 | 0.4%
| | Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-25699 | Apache | medium | 6.1 | 0.4%
| | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
T… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-33582 | Apache | medium | 6.5 | 0.5%
| | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-34031 | Apache | medium | 6.5 | 0.4%
| | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-34033 | Apache | medium | 5.4 | 0.4%
| | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-34905 | Apache | medium | 6.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This iss… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-49818 | Apache | medium | 6.5 | 0.7%
| | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destinat… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2025-67862 | Fortinet | medium | 6.0 | 0.1%
| | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili… | Jun 9, 2026 | Aug 11, 2026 |
| | CVE-2026-25089 | Fortinet | critical | 9.8 | 36.1%
| ⚠ KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-49938 | Fortinet | medium | 6.5 | 0.2%
| | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-41108 | Microsoft | high | 7.0 | — | | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-40409 | Microsoft | high | 7.8 | — | | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-40404 | Microsoft | high | 7.8 | — | | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-33828 | Microsoft | high | 7.8 | — | | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges … | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-34335 | Microsoft | high | 7.0 | — | | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-45487 | Microsoft | high | 7.8 | — | | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows … | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-45605 | Microsoft | high | 7.8 | — | | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-45640 | Microsoft | high | 7.0 | — | | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges … | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-45607 | Microsoft | high | 8.4 | — | | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jun 10, 2026 |