| | CVE-2026-45927 | Red Hat | medium | 6.3 | 0.0%
| | A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) subsystem. This vulnerability, a… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-45891 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's hns3 network driver. This double-free vulnerability occurs du… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-45945 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Intel VT-d (Virtualization Technology for Directed I/O) imple… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-45857 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's `scsi: csiostor` module. This null pointer dereference vulner… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-45848 | Red Hat | medium | — | 0.0%
| | A flaw was found in the Linux kernel's AppArmor security module. This vulnerability allows a local a… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-45933 | Red Hat | low | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's BPF (Berkeley Packet Filter) verifier. The `sync_linked_regs(… | May 27, 2026 | May 27, 2026 |
| | CVE-2026-48710 | Red Hat | high | 6.5 | 0.0%
| | A flaw was found in Starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework.… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-48863 | Red Hat | high | 7.5 | — | | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verificat… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-40564 | Apache | medium | 6.5 | 0.5%
| | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit… | May 26, 2026 | Jul 24, 2026 |
| | CVE-2026-48864 | Red Hat | medium | 7.8 | — | | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-4480 | Red Hat | high | 8.5 | — | | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-7374 | Red Hat | high | 9.9 | — | | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated Op… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-9530 | Red Hat | low | 3.3 | 0.0%
| | A flaw was found in GNU LibreDWG, specifically within the Dwgbmp Utility component. A local attacker… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-3592 | Red Hat | medium | 5.3 | 0.0%
| | A flaw was found in BIND resolvers. A remote attacker could exploit this vulnerability by sending a … | May 26, 2026 | May 26, 2026 |
| | CVE-2026-5950 | Red Hat | medium | 5.3 | 0.1%
| | A flaw was found in BIND 9. A remote, unauthenticated attacker can exploit an unbounded resend loop … | May 26, 2026 | May 26, 2026 |
| | CVE-2026-32792 | Red Hat | medium | 5.9 | 0.1%
| | A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending a specially… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-4408 | Red Hat | high | 9.0 | 0.2%
| | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers an… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-45836 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP subsystem. This vulnerability, a null-pointer… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-45834 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-45835 | Red Hat | medium | 5.5 | 0.0%
| | A flaw was found in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol… | May 26, 2026 | May 26, 2026 |
| | CVE-2026-48589 | Apache | medium | 5.4 | 0.4%
| | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-44598 | Apache | medium | 5.4 | 0.4%
| | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-43828 | Apache | medium | 6.5 | 0.3%
| | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-43827 | Apache | medium | 6.5 | 0.4%
| | Default configurations of Apache Shiro have a session fixation vulnerability.
This issue affects Ap… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-42797 | Apache | medium | 4.9 | 0.4%
| | Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administ… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-42782 | Apache | high | 7.2 | 0.7%
| | Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with a… | May 25, 2026 | Jul 24, 2026 |
| | CVE-2026-46745 | Apache | medium | 5.3 | 0.6%
| | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-45361 | Apache | high | 8.1 | 0.6%
| | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defau… | May 25, 2026 | Jul 21, 2026 |
| | CVE-2026-45249 | Apache | medium | 6.1 | 0.8%
| | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rend… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-41863 | VMware | medium | 6.5 | 0.4%
| | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.res… | May 25, 2026 | Jul 23, 2026 |
| | CVE-2026-2651 | Red Hat | critical | 9.0 | 0.1%
| | A flaw was found in MLflow when the `--serve-artifacts` mode is enabled. A remote attacker can explo… | May 25, 2026 | May 25, 2026 |
| | CVE-2026-9298 | Red Hat | medium | 6.3 | 0.0%
| | A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an u… | May 23, 2026 | May 23, 2026 |
| | CVE-2026-43503 | Red Hat | high | 7.0 | 0.0%
| | A flaw was found in the Linux kernel's networking (skbuff) component. When skb_try_coalesce() attach… | May 23, 2026 | May 23, 2026 |
| | CVE-2026-47280 | Microsoft | critical | 10.0 | 0.5%
| | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate p… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-42901 | Microsoft | critical | 10.0 | 0.3%
| | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-42827 | Microsoft | medium | 6.5 | 0.5%
| | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-41104 | Microsoft | critical | 10.0 | 0.9%
| | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacke… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-41090 | Microsoft | critical | 9.3 | 0.4%
| | Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-40412 | Microsoft | critical | 10.0 | 0.5%
| | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attac… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-40411 | Microsoft | critical | 9.9 | 0.5%
| | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-35430 | Microsoft | high | 8.8 | 0.4%
| | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allow… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-33843 | Microsoft | critical | 9.1 | 0.5%
| | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C all… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-26147 | Microsoft | high | 7.7 | 0.6%
| | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose informa… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-23663 | Microsoft | high | 7.5 | 0.6%
| | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privilege… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-23652 | Microsoft | critical | 10.0 | 0.6%
| | Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow… | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-45659 | Microsoft | high | 8.8 | 9.1%
| ⚠ KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 22, 2026 | Aug 11, 2026 |
| | CVE-2026-9256 | F5 | high | 8.1 | 10.0%
| | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vu… | May 22, 2026 | Aug 25, 2026 |
| | CVE-2026-9277 | Red Hat | high | 8.1 | 0.1%
| | A flaw was found in the shell-quote component. The quote() function did not properly validate object… | May 22, 2026 | May 22, 2026 |
| | CVE-2026-44930 | Apache | critical | 9.8 | 0.7%
| | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF … | May 22, 2026 | Jul 23, 2026 |
| | CVE-2026-44618 | Apache | medium | 5.3 | 0.3%
| | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform … | May 22, 2026 | Jul 23, 2026 |