| | CVE-2026-83607 | Red Hat | high | 8.1 | — | | A flaw was found in xmldom, a JavaScript module for parsing and serializing XML. This vulnerability … | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83606 | Red Hat | high | 7.5 | — | | A flaw was found in xmldom, a JavaScript XML DOM parser. This vulnerability, a Regular Expression De… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-83605 | Red Hat | high | 8.1 | — | | A flaw was found in xmldom, a JavaScript XML DOM parser. The Element.setAttribute() function does no… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84233 | Red Hat | medium | 7.0 | — | | A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containin… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84218 | Apache | high | 8.1 | — | | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co… | Sep 1, 2026 | Sep 2, 2026 |
| | CVE-2026-84127 | Red Hat | medium | 6.5 | — | | A flaw was found in the WebExtensions component of Firefox for Android. This vulnerability allows fo… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84125 | Red Hat | high | 8.8 | — | | A flaw was found in Firefox. A use-after-free vulnerability in the DOM: Core & HTML component could … | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84131 | Red Hat | high | 8.2 | — | | A flaw was found in the Graphics component of Firefox. An invalid pointer could allow a local attack… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84120 | Red Hat | high | 8.8 | — | | A flaw was found in the Audio/Video component of Firefox and Firefox ESR. This use-after-free vulner… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-11873 | Red Hat | medium | 6.5 | — | | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 5… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-53682 | Red Hat | medium | 5.3 | — | | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDom… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84232 | Red Hat | medium | 5.4 | — | | A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type reposit… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-84470 | Red Hat | medium | 6.4 | — | | A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job Launch A… | Sep 1, 2026 | Sep 1, 2026 |
| | CVE-2026-82346 | HPE | medium | — | 0.1%
| | A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.… | Aug 31, 2026 | Sep 3, 2026 |
| | CVE-2026-17615 | Apache | high | 7.5 | 0.3%
| | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker… | Aug 31, 2026 | Sep 4, 2026 |
| | CVE-2026-76986 | Apache | medium | 6.1 | 0.3%
| | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-76985 | Apache | medium | 5.4 | 0.4%
| | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.ext… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-12894 | Apache | high | 8.8 | 0.3%
| | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content l… | Aug 31, 2026 | Sep 3, 2026 |
| | CVE-2026-76984 | Apache | medium | 5.4 | 0.4%
| | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-76983 | Apache | medium | 5.4 | 0.4%
| | Improper neutralization of input during web page generation in Apache Wicket.
The <wicket:label> ta… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-76982 | Apache | medium | 5.4 | 0.4%
| | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-75802 | Apache | medium | 5.4 | 0.4%
| | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writ… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-71378 | Apache | medium | 4.6 | 0.1%
| | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forge… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-71257 | Apache | high | 7.5 | 0.2%
| | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multip… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-70449 | Apache | medium | 5.3 | 0.5%
| | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote att… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-58301 | Apache | medium | 6.5 | 0.2%
| | When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an… | Aug 31, 2026 | Sep 1, 2026 |
| | CVE-2026-80725 | Red Hat | high | 7.0 | 0.2%
| | In the Linux kernel, the following vulnerability has been resolved:
net: gro: properly validate BIG … | Aug 29, 2026 | Aug 29, 2026 |
| | CVE-2026-72984 | Microsoft | high | 8.8 | 0.4%
| | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all… | Aug 28, 2026 | Sep 1, 2026 |
| | CVE-2026-70331 | Microsoft | medium | 5.4 | 0.3%
| | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthor… | Aug 28, 2026 | Sep 1, 2026 |
| | CVE-2026-70309 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass… | Aug 28, 2026 | Aug 31, 2026 |
| | CVE-2026-66798 | Microsoft | medium | 4.3 | 0.6%
| | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov… | Aug 28, 2026 | Sep 1, 2026 |
| | CVE-2026-66324 | Microsoft | medium | 6.5 | 0.7%
| | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized atta… | Aug 28, 2026 | Aug 31, 2026 |
| | CVE-2026-66323 | Microsoft | medium | 5.4 | 0.3%
| | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows a… | Aug 28, 2026 | Aug 31, 2026 |
| | CVE-2026-62904 | Microsoft | medium | 5.4 | 0.3%
| | Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo… | Aug 28, 2026 | Aug 31, 2026 |
| | CVE-2026-58616 | Microsoft | medium | 4.4 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Copil… | Aug 28, 2026 | Aug 31, 2026 |
| | CVE-2026-56854 | Red Hat | critical | 9.1 | 0.3%
| | The source-address critical option in the Permissions returned by an authentication callback was onl… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-82327 | Red Hat | medium | 5.5 | 0.1%
| | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80612 | Red Hat | medium | 5.5 | 0.4%
| | In the Linux kernel, the following vulnerability has been resolved:
net: lwtunnel: Drop skb metadata… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80673 | Red Hat | medium | 5.5 | 0.4%
| | In the Linux kernel, the following vulnerability has been resolved:
ntfs: bound the look-ahead attri… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80661 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
ufs: core: tracing: Do not deref… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80603 | Red Hat | medium | 7.0 | 0.4%
| | In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_irc: fix… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80677 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
driver core: use READ_ONCE() for… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80718 | Red Hat | medium | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
mm/percpu-km: fix bitmap overflo… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80697 | Red Hat | medium | 5.5 | 0.2%
| | In the Linux kernel, the following vulnerability has been resolved:
erofs: ensure valid f_path for p… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80700 | Red Hat | medium | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: validate external BO… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80664 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_nat: reject unsupp… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80689 | Red Hat | low | 5.5 | 0.2%
| | In the Linux kernel, the following vulnerability has been resolved:
tracing/mmiotrace: Add NULL chec… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80694 | Red Hat | medium | 5.5 | 0.5%
| | In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: mtk_eth_soc: pass… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80618 | Red Hat | medium | 5.5 | 0.2%
| | In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Avoid double-unpin o… | Aug 28, 2026 | Aug 28, 2026 |
| | CVE-2026-80599 | Red Hat | medium | 5.5 | 0.3%
| | In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: ensure accessib… | Aug 28, 2026 | Aug 28, 2026 |