| | CVE-2026-84428 | Red Hat | high | 7.5 | — | | A flaw was found in fastify. Due to incomplete case normalization of HTTP header names within a rout… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84469 | Red Hat | high | 7.5 | 0.5%
| | A flaw was found in fastify. An unauthenticated remote attacker can bypass request validation by exp… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-76169 | Red Hat | high | 7.5 | 0.5%
| | A flaw was found in fastify. Malformed URLs can be routed to a custom not-found handler of a differe… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84504 | Red Hat | high | 8.1 | 0.4%
| | A flaw was found in fastify. An authenticated low-privilege caller can exploit a vulnerability where… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71198 | Red Hat | high | 7.7 | — | | A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. When the HTTP stor… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71197 | Red Hat | medium | 4.3 | — | | A flaw was found in OpenStack Glance. The web-download image import method can bypass host-based blo… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-81665 | Red Hat | high | 7.5 | 0.2%
| | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembl… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71196 | Red Hat | high | 7.7 | — | | A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. The web-download i… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85525 | Red Hat | high | 7.4 | 0.1%
| | A flaw was found in Snowflake drivers, including Python, Go, JDBC, and Node.js. This flaw involves i… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-81666 | Red Hat | medium | 6.5 | 0.3%
| | An integer overflow was found in Corosync's handling of membership commit token messages. The length… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-80190 | Apache | medium | — | — | | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected.… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85229 | Apache | medium | — | — | | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-81270 | Apache | medium | — | — | | Apache Allura: exposure of non-public information via search.
This issue affects Apache Allura: t… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71216 | Apache | medium | — | — | | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty serves … | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-80181 | Apache | medium | — | — | | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affect… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-80180 | Apache | medium | — | — | | Stored XSS via markdown HTML processing in Apache Allura.
This issue affects Apache Allura: from … | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85509 | Red Hat | high | 8.8 | 0.4%
| | A flaw was found in FreeIPMI. This vulnerability is a stack-based buffer overflow in the _read_fru_d… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85508 | Red Hat | medium | 7.5 | 0.4%
| | A stack-based buffer overflow exists in FreeIPMI's ipmi-oem tool, in the Dell OEM handler for the ge… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85507 | Red Hat | high | 8.8 | 0.4%
| | A flaw was found in FreeIPMI. This vulnerability, a stack-based buffer overflow in the `ipmi-oem` co… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85506 | Red Hat | high | 8.8 | 0.4%
| | A flaw was found in FreeIPMI. This vulnerability, a stack-based buffer overflow in the `ipmi-oem` co… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85505 | Red Hat | medium | 6.5 | 0.3%
| | A stack-based out-of-bounds read vulnerability was found in the FreeIPMI ipmi-oem utility. When proc… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85504 | Red Hat | high | 8.8 | 0.4%
| | A flaw was found in FreeIPMI. This vulnerability, a stack-based buffer overflow, could allow a remot… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85498 | Red Hat | low | 3.5 | — | | No description is available for this CVE. | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85063 | Red Hat | medium | 6.5 | — | | A flaw was found in node-csv, specifically within its csv-parse component. When configured with colu… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-84185 | Red Hat | medium | 5.9 | — | | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing a… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71429 | Red Hat | medium | 6.2 | — | | A flaw was found in stream-json. This vulnerability allows a remote attacker to cause a Denial of Se… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85049 | Red Hat | high | 8.8 | — | | An use after free flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
htt… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85396 | Red Hat | high | 7.5 | — | | A flaw was found in rubyzip. This path traversal vulnerability in the Zip::Entry#extract function al… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85393 | Red Hat | high | 7.5 | — | | A flaw was found in node-forge. This vulnerability allows a remote attacker to forge valid RSA PKCS#… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71224 | Red Hat | medium | 4.7 | — | | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses al… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71223 | Red Hat | medium | 7.0 | — | | An integer overflow vulnerability was found in gfs2-utils. The resource group allocation size comput… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71222 | Red Hat | medium | 5.3 | — | | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk … | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71221 | Red Hat | medium | 7.0 | — | | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value fro… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71220 | Red Hat | medium | 7.0 | — | | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-71219 | Red Hat | medium | 4.7 | — | | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c … | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85150 | Red Hat | medium | 7.5 | — | | A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occ… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85089 | Red Hat | medium | 6.5 | 0.4%
| | A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disc… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85090 | Red Hat | medium | 5.4 | 0.3%
| | A flaw was found in FreeRDP. A heap out-of-bounds read vulnerability exists in the `general_ChromaV1… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-85218 | Red Hat | high | 7.1 | — | | A double stack-based buffer overflow was found in the BlueZ AVRCP controller implementation. A nearb… | Sep 3, 2026 | Sep 3, 2026 |
| | CVE-2026-84452 | Microsoft | medium | — | 0.9%
| | Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models … | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20355 | Cisco | medium | 5.9 | — | | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption fun… | Sep 2, 2026 | Sep 2, 2026 |
| | CVE-2026-20354 | Cisco | medium | 5.9 | — | | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption fun… | Sep 2, 2026 | Sep 2, 2026 |
| | CVE-2026-20281 | Cisco | high | 7.5 | — | | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Vide… | Sep 2, 2026 | Sep 2, 2026 |
| | CVE-2026-20280 | Cisco | high | 8.8 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS … | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20279 | Cisco | critical | 9.8 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20278 | Cisco | high | 8.8 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20277 | Cisco | high | 8.2 | 0.2%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20276 | Cisco | high | 8.6 | — | | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 2, 2026 |
| | CVE-2026-20275 | Cisco | high | 8.8 | 0.2%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 3, 2026 |
| | CVE-2026-20274 | Cisco | critical | 9.8 | 0.7%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR So… | Sep 2, 2026 | Sep 3, 2026 |