| | CVE-2026-44615 | Apache | medium | 6.5 | 0.5%
| | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authe… | Jul 31, 2026 | Aug 10, 2026 |
| | CVE-2026-62391 | Apache | high | 8.1 | 0.4%
| | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server… | Jul 31, 2026 | Aug 10, 2026 |
| | CVE-2026-64607 | Apache | medium | 5.3 | 0.3%
| | HttpClient based on the classic i/o model fails to correctly release the underlying connection back … | Jul 31, 2026 | Aug 13, 2026 |
| | CVE-2026-18358 | Red Hat | medium | 7.5 | 0.4%
| | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is … | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-18141 | Red Hat | high | 8.2 | 0.3%
| | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-17348 | Red Hat | medium | 6.5 | 0.2%
| | A flaw was found in pgAdmin 4. In SERVER mode, an unauthenticated network client could exploit missi… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-17566 | Red Hat | critical | 9.9 | 0.4%
| | A flaw was found in pgAdmin 4, a management tool for PostgreSQL databases. The Import/Export Data fe… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-18651 | Red Hat | medium | 5.4 | — | | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs conn… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68743 | Red Hat | medium | 5.5 | — | | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate t… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68742 | Red Hat | medium | 5.5 | — | | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not v… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68744 | Red Hat | low | 3.3 | — | | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-alloc… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-18574 | Check Point | critical | 9.3 | 1.0%
| | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Se… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68945 | Red Hat | high | 8.2 | — | | A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP req… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-69151 | Red Hat | high | 8.1 | — | | A flaw was found in the Angular compiler's internationalization (i18n) pipeline. This vulnerability … | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-69152 | Red Hat | high | 7.5 | — | | A flaw was found in the brace-expansion library. An attacker can provide specially crafted input to … | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-69153 | Red Hat | high | 7.5 | — | | A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a special… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-61372 | Apache | high | 7.5 | 0.6%
| | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac… | Aug 3, 2026 | Aug 7, 2026 |
| | CVE-2026-18739 | Red Hat | low | 2.5 | — | | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuf… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-62354 | Apache | medium | 4.3 | 0.3%
| | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.… | Aug 3, 2026 | Aug 10, 2026 |
| | CVE-2026-68979 | Apache | critical | 9.8 | 0.4%
| | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not e… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68980 | Apache | critical | 9.1 | 0.3%
| | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Para… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68981 | Apache | high | 7.5 | 0.3%
| | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API usi… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-18667 | Tenable | critical | 9.6 | 0.4%
| | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privi… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-64561 | Red Hat | high | 7.0 | 0.2%
| | A flaw was found in KVM in the Linux kernel. This vulnerability occurs due to improper validation of… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-62870 | Microsoft | high | 8.8 | 0.8%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a netw… | Aug 4, 2026 | Aug 9, 2026 |
| | CVE-2026-65802 | Microsoft | high | 7.4 | 0.9%
| | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker … | Aug 4, 2026 | Aug 7, 2026 |
| | CVE-2026-65804 | Microsoft | medium | 6.1 | 0.4%
| | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66310 | Microsoft | high | 7.7 | 0.4%
| | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker … | Aug 4, 2026 | Aug 7, 2026 |
| | CVE-2026-66311 | Microsoft | medium | 6.2 | 0.4%
| | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66312 | Microsoft | medium | 6.5 | 1.0%
| | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code ov… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66313 | Microsoft | medium | 6.8 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66314 | Microsoft | medium | 6.5 | 0.7%
| | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unaut… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66315 | Microsoft | high | 7.5 | 0.6%
| | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66316 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66317 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66318 | Microsoft | high | 8.1 | 0.4%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66321 | Microsoft | high | 7.4 | 0.9%
| | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66322 | Microsoft | high | 7.1 | 0.3%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66325 | Microsoft | medium | 6.1 | 0.4%
| | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66326 | Microsoft | medium | 6.5 | 0.7%
| | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-42170 | Red Hat | high | 7.8 | — | | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. … | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-42169 | Red Hat | medium | 7.3 | 0.1%
| | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This fla… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-17614 | Red Hat | medium | 4.4 | 0.9%
| | A path traversal flaw was found in WildFly's domain mode
implementation. The LocalFileRepository.get… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-70367 | Red Hat | medium | 5.4 | — | | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when co… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-70368 | Red Hat | medium | 6.5 | — | | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when hand… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-58067 | Veeam | medium | — | 0.4%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust ho… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58071 | Veeam | medium | — | 0.4%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58072 | Veeam | medium | — | 0.5%
| | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management se… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58073 | Veeam | medium | — | 0.3%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonat… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58074 | Veeam | medium | — | 0.4%
| | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | Aug 4, 2026 | Sep 3, 2026 |