| | CVE-2026-59230 | Apache | medium | 6.5 | 0.4%
| | Improper input validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 2.… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-60093 | Apache | medium | 5.5 | 0.3%
| | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component
This issue… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-63621 | Apache | medium | 5.3 | 0.4%
| | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-66906 | Apache | critical | 9.1 | 0.5%
| | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.
This issue af… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-66907 | Apache | high | 7.5 | 0.6%
| | Relative path traversal vulnerability in Apache Camel Google Storage component.
This issue affect… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-66908 | Apache | high | 7.5 | 0.4%
| | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.
This issue af… | Aug 24, 2026 | Aug 28, 2026 |
| | CVE-2026-71300 | Apache | critical | 9.8 | 0.5%
| | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.
This issu… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-75099 | Apache | medium | 5.3 | 0.4%
| | Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apa… | Aug 24, 2026 | Aug 28, 2026 |
| | CVE-2026-78329 | Apache | critical | 9.8 | 0.4%
| | Improper input validation vulnerability in Apache Camel Undertow component.
This issue affects Ap… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-76098 | Red Hat | high | 7.5 | 0.3%
| | Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-75509 | Red Hat | medium | 6.5 | 0.1%
| | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encry… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-17113 | Red Hat | medium | 6.0 | 0.1%
| | A flaw was found in CRI-O's container-creation environment-variable handling
(`mergeEnvs` in `server… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-68516 | Red Hat | medium | 6.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-53532 | Red Hat | medium | 6.5 | 0.3%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-80185 | Red Hat | medium | 5.7 | 0.2%
| | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80186 | Red Hat | high | 7.6 | 0.4%
| | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A r… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-52491 | Red Hat | high | 7.3 | 0.2%
| ✓ Fix | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63074 | Red Hat | low | 7.5 | 0.5%
| ✓ Fix | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (ext… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63073 | Red Hat | low | 5.9 | 0.4%
| ✓ Fix | Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished na… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-54874 | Red Hat | low | 7.5 | 0.5%
| ✓ Fix | Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes Op… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-14457 | Red Hat | low | 7.5 | 1.0%
| ✓ Fix | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63076 | Red Hat | medium | 7.5 | 1.3%
| ✓ Fix | Issue summary: OpenSSL CMP password based protection verification only
checks whether the protection… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63072 | Red Hat | medium | 7.5 | 0.6%
| ✓ Fix | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwra… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-18798 | Red Hat | medium | 7.5 | 1.5%
| ✓ Fix | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation f… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-54920 | Red Hat | medium | 6.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55059 | Red Hat | medium | 5.5 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55371 | Red Hat | medium | 5.5 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55373 | Red Hat | medium | 6.2 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-59183 | Red Hat | medium | 5.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-19542 | Red Hat | medium | 4.2 | — | ✓ Fix | A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` fu… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-19499 | Red Hat | medium | 6.8 | — | ✓ Fix | A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow w… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-77117 | Red Hat | medium | 5.9 | — | | A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-49845 | Apache | medium | — | 0.5%
| | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on … | Aug 25, 2026 | Sep 4, 2026 |
| | CVE-2026-49050 | Apache | high | 8.8 | 0.3%
| | General user can mint admin access tokens via /access-tokens
This issue affects Apache DolphinSch… | Aug 25, 2026 | Sep 9, 2026 |
| | CVE-2026-53561 | Apache | high | 7.4 | 0.3%
| | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive … | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-55976 | Apache | critical | 9.1 | 0.6%
| | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allow… | Aug 25, 2026 | Aug 28, 2026 |
| | CVE-2026-78684 | Red Hat | medium | 5.3 | 0.3%
| | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enfo… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79717 | Red Hat | medium | 6.4 | 0.2%
| | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-78360 | Red Hat | high | 7.1 | — | | A missing authorization flaw was found in Anitya. The user deletion endpoint checks that the caller … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-16599 | Red Hat | medium | 6.5 | 0.4%
| | GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80184 | Red Hat | high | 7.1 | 0.5%
| | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80182 | Red Hat | high | 8.1 | 0.5%
| | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2022-50998 | Red Hat | high | 7.5 | 0.4%
| | Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, whic… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2021-47996 | Red Hat | high | 7.5 | 0.5%
| | Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundl… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2022-50999 | Red Hat | high | 7.0 | 0.3%
| | Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2023-54354 | Red Hat | medium | 5.9 | 0.4%
| | Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2025-71346 | Red Hat | low | 2.9 | 0.2%
| | Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2025-71406 | Red Hat | high | 7.8 | 0.2%
| | Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two u… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79674 | Red Hat | high | 7.5 | 0.2%
| | NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructor… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79676 | Red Hat | medium | 5.9 | 0.3%
| | NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen roo… | Aug 25, 2026 | Aug 25, 2026 |