| | CVE-2026-66322 | Microsoft | high | 7.1 | 0.3%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66321 | Microsoft | high | 7.4 | 0.9%
| | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66318 | Microsoft | high | 8.1 | 0.4%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66317 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66316 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66315 | Microsoft | high | 7.5 | 0.6%
| | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66314 | Microsoft | medium | 6.5 | 0.7%
| | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unaut… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66313 | Microsoft | medium | 6.8 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66312 | Microsoft | medium | 6.5 | 1.0%
| | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code ov… | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66311 | Microsoft | medium | 6.2 | 0.4%
| | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66310 | Microsoft | high | 7.7 | 0.4%
| | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker … | Aug 4, 2026 | Aug 7, 2026 |
| | CVE-2026-65804 | Microsoft | medium | 6.1 | 0.4%
| | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-65802 | Microsoft | high | 7.4 | 0.9%
| | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker … | Aug 4, 2026 | Aug 7, 2026 |
| | CVE-2026-62870 | Microsoft | high | 8.8 | 0.8%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a netw… | Aug 4, 2026 | Aug 9, 2026 |
| | CVE-2026-64561 | Red Hat | high | 7.0 | 0.2%
| | A flaw was found in KVM in the Linux kernel. This vulnerability occurs due to improper validation of… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-18667 | Tenable | critical | 9.6 | 0.4%
| | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privi… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68981 | Apache | high | 7.5 | 0.3%
| | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API usi… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68980 | Apache | critical | 9.1 | 0.3%
| | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Para… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68979 | Apache | critical | 9.8 | 0.4%
| | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not e… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-62354 | Apache | medium | 4.3 | 0.3%
| | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.… | Aug 3, 2026 | Aug 10, 2026 |
| | CVE-2026-18739 | Red Hat | low | 2.5 | — | | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuf… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-61372 | Apache | high | 7.5 | 0.6%
| | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac… | Aug 3, 2026 | Aug 7, 2026 |
| | CVE-2026-69153 | Red Hat | high | 7.5 | — | | A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a special… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-69152 | Red Hat | high | 7.5 | — | | A flaw was found in the brace-expansion library. An attacker can provide specially crafted input to … | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-69151 | Red Hat | high | 8.1 | — | | A flaw was found in the Angular compiler's internationalization (i18n) pipeline. This vulnerability … | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68945 | Red Hat | high | 8.2 | — | | A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP req… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-18574 | Check Point | critical | 9.3 | 1.0%
| | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Se… | Aug 3, 2026 | Aug 5, 2026 |
| | CVE-2026-68744 | Red Hat | low | 3.3 | — | | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-alloc… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68742 | Red Hat | medium | 5.5 | — | | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not v… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-68743 | Red Hat | medium | 5.5 | — | | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate t… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-18651 | Red Hat | medium | 5.4 | — | | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs conn… | Aug 3, 2026 | Aug 3, 2026 |
| | CVE-2026-17566 | Red Hat | critical | 9.9 | 0.4%
| | A flaw was found in pgAdmin 4, a management tool for PostgreSQL databases. The Import/Export Data fe… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-17348 | Red Hat | medium | 6.5 | 0.2%
| | A flaw was found in pgAdmin 4. In SERVER mode, an unauthenticated network client could exploit missi… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-18141 | Red Hat | high | 8.2 | 0.3%
| | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-18358 | Red Hat | medium | 7.5 | 0.4%
| | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is … | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-64607 | Apache | medium | 5.3 | 0.3%
| | HttpClient based on the classic i/o model fails to correctly release the underlying connection back … | Jul 31, 2026 | Aug 13, 2026 |
| | CVE-2026-62391 | Apache | high | 8.1 | 0.4%
| | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server… | Jul 31, 2026 | Aug 10, 2026 |
| | CVE-2026-44615 | Apache | medium | 6.5 | 0.5%
| | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authe… | Jul 31, 2026 | Aug 10, 2026 |
| | CVE-2026-18569 | Red Hat | low | 3.7 | — | | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is par… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-10079 | Red Hat | high | 8.5 | 0.2%
| | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubern… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-11770 | Red Hat | medium | 7.5 | 0.5%
| | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search … | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-15722 | Red Hat | high | 7.5 | 0.5%
| | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_fro… | Jul 31, 2026 | Jul 31, 2026 |
| | CVE-2026-66803 | Microsoft | critical | 10.0 | 0.5%
| | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne… | Jul 30, 2026 | Aug 4, 2026 |
| | CVE-2026-68563 | Red Hat | medium | 5.5 | — | | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevat… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-68562 | Red Hat | medium | 6.2 | — | | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a m… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-66756 | Apache | critical | 9.8 | 0.3%
| | Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika:… | Jul 30, 2026 | Aug 10, 2026 |
| | CVE-2026-66755 | Apache | high | 7.5 | 0.4%
| | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 thr… | Jul 30, 2026 | Sep 1, 2026 |
| | CVE-2026-18157 | Red Hat | high | 7.8 | — | | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the s… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-52680 | Apache | critical | 9.8 | 0.5%
| | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when … | Jul 30, 2026 | Aug 5, 2026 |
| | CVE-2026-48910 | Apache | medium | 6.5 | 0.3%
| | A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsi… | Jul 30, 2026 | Aug 5, 2026 |