| | CVE-2026-17938 | Red Hat | low | 0.0 | 0.2%
| | An inappropriate implementation flaw was found in the FullScreen component of the Chromium browser.
… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17940 | Red Hat | low | 0.0 | 0.2%
| | An insufficient validation of untrusted input flaw was found in the Picture-in-Picture component of … | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17939 | Red Hat | low | 4.3 | — | | An inappropriate implementation flaw was found in the Passwords component of the Chromium browser.
U… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17943 | Red Hat | low | 4.3 | 0.2%
| | An inappropriate implementation flaw was found in the Parser component of the Chromium browser.
Upst… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17942 | Red Hat | low | 4.3 | 0.2%
| | A side-channel information leakage flaw was found in the SVG component of the Chromium browser.
Upst… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17945 | Red Hat | low | 2.8 | 0.2%
| | An inappropriate implementation flaw was found in the Navigation component of the Chromium browser.
… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17946 | Red Hat | low | 2.8 | 0.2%
| | An uninitialized use flaw was found in the Dawn component of the Chromium browser.
Upstream bug(s):
… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17947 | Red Hat | low | 0.0 | 0.2%
| | An use after free flaw was found in the WebSockets component of the Chromium browser.
Upstream bug(s… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17948 | Red Hat | low | 4.2 | 0.1%
| | A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https:… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17949 | Red Hat | low | 4.3 | 0.2%
| | An uninitialized use flaw was found in the GPU component of the Chromium browser.
Upstream bug(s):
h… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17950 | Red Hat | low | 4.3 | 0.2%
| | A policy bypass flaw was found in the Safebrowsing component of the Chromium browser.
Upstream bug(s… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17951 | Red Hat | low | 4.3 | 0.2%
| | A heap buffer overflow flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17952 | Red Hat | low | 0.0 | 0.1%
| | An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17953 | Red Hat | low | 4.3 | — | | An insufficient policy enforcement flaw was found in the WebView component of the Chromium browser.
… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17954 | Red Hat | low | 4.3 | 0.2%
| | A policy bypass flaw was found in the MHTML component of the Chromium browser.
Upstream bug(s):
http… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17955 | Red Hat | low | 4.3 | 0.2%
| | An insufficient validation of untrusted input flaw was found in the Payments component of the Chromi… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17962 | Red Hat | low | 5.4 | — | | An inappropriate implementation flaw was found in the Blink component of the Chromium browser.
Upstr… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17975 | Red Hat | low | 4.3 | — | | An inappropriate implementation flaw was found in the IME component of the Chromium browser.
Upstrea… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-17983 | Red Hat | low | 4.3 | — | | An incorrect security ui flaw was found in the Global Media Controls component of the Chromium brows… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-18002 | Red Hat | low | 5.0 | — | | An insufficient validation of untrusted input flaw was found in the Google Lens component of the Chr… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-18005 | Red Hat | low | 4.3 | — | | An inappropriate implementation flaw was found in the WebXR component of the Chromium browser.
Upstr… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-56850 | Red Hat | medium | 4.1 | 0.1%
| ✓ Fix | A flaw was found in Node.js. The HTTPS Agent, responsible for managing secure connections, can incor… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-64635 | Veeam | medium | 5.3 | 0.2%
| | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provid… | Jul 30, 2026 | Sep 3, 2026 |
| | CVE-2026-18369 | Red Hat | medium | 5.8 | — | | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP add… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-47876 | VMware | critical | 9.3 | — | | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A m… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-41703 | VMware | high | 7.6 | — | | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor w… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-41709 | VMware | low | 2.7 | — | | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit t… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-59309 | VMware | critical | 9.8 | 7.9%
| | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A ma… | Jul 30, 2026 | Aug 25, 2026 |
| | CVE-2026-59310 | VMware | critical | 9.8 | 1.1%
| ⚠ KEV | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor … | Jul 30, 2026 | Aug 19, 2026 |
| | CVE-2026-23981 | Apache | medium | 4.3 | 0.3%
| | An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user wit… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-23985 | Apache | medium | 6.5 | 0.3%
| | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-28811 | Apache | high | 7.5 | 0.3%
| | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.
Users are recommend… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-28812 | Apache | critical | 9.8 | 0.3%
| | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attac… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-28813 | Apache | high | 8.8 | 0.1%
| | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-28814 | Apache | high | 7.5 | 0.3%
| | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows … | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-44613 | Apache | medium | 6.1 | 0.4%
| | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration a… | Jul 30, 2026 | Aug 7, 2026 |
| | CVE-2026-44616 | Apache | medium | 6.5 | 0.3%
| | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search f… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-44617 | Apache | medium | 6.5 | 0.4%
| | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name e… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-48910 | Apache | medium | 6.5 | 0.3%
| | A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsi… | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-52680 | Apache | critical | 9.8 | 0.5%
| | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when … | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-18157 | Red Hat | high | 7.8 | — | | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the s… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-66755 | Apache | high | 7.5 | 0.4%
| | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 thr… | Jul 30, 2026 | Sep 1, 2026 |
| | CVE-2026-66756 | Apache | critical | 9.8 | 0.3%
| | Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika:… | Jul 30, 2026 | Aug 10, 2026 |
| | CVE-2026-68562 | Red Hat | medium | 6.2 | — | | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a m… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-68563 | Red Hat | medium | 5.5 | — | | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevat… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-66803 | Microsoft | critical | 10.0 | 0.5%
| | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne… | Jul 30, 2026 | Aug 4, 2026 |
| | CVE-2026-15722 | Red Hat | high | 7.5 | 0.5%
| | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_fro… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-11770 | Red Hat | medium | 7.5 | 0.5%
| | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search … | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-10079 | Red Hat | high | 8.5 | 0.2%
| | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubern… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-18569 | Red Hat | low | 3.7 | — | | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is par… | Jul 31, 2026 | Jul 31, 2026 |