| | CVE-2021-47996 | Red Hat | high | 7.5 | 0.5%
| | Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundl… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2022-50998 | Red Hat | high | 7.5 | 0.4%
| | Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, whic… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80182 | Red Hat | high | 8.1 | 0.5%
| | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80184 | Red Hat | high | 7.1 | 0.5%
| | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-16599 | Red Hat | medium | 6.5 | 0.4%
| | GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-78360 | Red Hat | high | 7.1 | — | | A missing authorization flaw was found in Anitya. The user deletion endpoint checks that the caller … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79717 | Red Hat | medium | 6.4 | 0.2%
| | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-78684 | Red Hat | medium | 5.3 | 0.3%
| | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enfo… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55976 | Apache | critical | 9.1 | 0.6%
| | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allow… | Aug 25, 2026 | Aug 28, 2026 |
| | CVE-2026-53561 | Apache | high | 7.4 | 0.3%
| | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive … | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-49845 | Apache | medium | — | 0.5%
| | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on … | Aug 25, 2026 | Sep 4, 2026 |
| | CVE-2026-77117 | Red Hat | medium | 5.9 | — | | A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-19499 | Red Hat | medium | 6.8 | — | ✓ Fix | A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow w… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-19542 | Red Hat | medium | 4.2 | — | ✓ Fix | A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` fu… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-59183 | Red Hat | medium | 5.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55373 | Red Hat | medium | 6.2 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55371 | Red Hat | medium | 5.5 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55059 | Red Hat | medium | 5.5 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-54920 | Red Hat | medium | 6.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-18798 | Red Hat | medium | 7.5 | 1.5%
| ✓ Fix | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation f… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63072 | Red Hat | medium | 7.5 | 0.6%
| ✓ Fix | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwra… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63076 | Red Hat | medium | 7.5 | 1.3%
| ✓ Fix | Issue summary: OpenSSL CMP password based protection verification only
checks whether the protection… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-14457 | Red Hat | low | 7.5 | 1.0%
| ✓ Fix | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-54874 | Red Hat | low | 7.5 | 0.5%
| ✓ Fix | Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes Op… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63073 | Red Hat | low | 5.9 | 0.4%
| ✓ Fix | Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished na… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63074 | Red Hat | low | 7.5 | 0.5%
| ✓ Fix | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (ext… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-52491 | Red Hat | high | 7.3 | 0.2%
| ✓ Fix | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80186 | Red Hat | high | 7.6 | 0.4%
| | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A r… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-80185 | Red Hat | medium | 5.7 | 0.2%
| | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-53532 | Red Hat | medium | 6.5 | 0.3%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-68516 | Red Hat | medium | 6.5 | 0.2%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-17113 | Red Hat | medium | 6.0 | 0.1%
| | A flaw was found in CRI-O's container-creation environment-variable handling
(`mergeEnvs` in `server… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-75509 | Red Hat | medium | 6.5 | 0.1%
| | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encry… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-76098 | Red Hat | high | 7.5 | 0.3%
| | Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-78329 | Apache | critical | 9.8 | 0.4%
| | Improper input validation vulnerability in Apache Camel Undertow component.
This issue affects Ap… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-75099 | Apache | medium | 5.3 | 0.4%
| | Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apa… | Aug 24, 2026 | Aug 28, 2026 |
| | CVE-2026-71300 | Apache | critical | 9.8 | 0.5%
| | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.
This issu… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-66908 | Apache | high | 7.5 | 0.4%
| | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.
This issue af… | Aug 24, 2026 | Aug 28, 2026 |
| | CVE-2026-66907 | Apache | high | 7.5 | 0.6%
| | Relative path traversal vulnerability in Apache Camel Google Storage component.
This issue affect… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-66906 | Apache | critical | 9.1 | 0.5%
| | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.
This issue af… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-63621 | Apache | medium | 5.3 | 0.4%
| | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-60093 | Apache | medium | 5.5 | 0.3%
| | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component
This issue… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-59230 | Apache | medium | 6.5 | 0.4%
| | Improper input validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 2.… | Aug 24, 2026 | Aug 27, 2026 |
| | CVE-2026-12556 | HPE | medium | — | 0.2%
| | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t… | Aug 24, 2026 | Sep 3, 2026 |
| | CVE-2026-12555 | HPE | medium | — | 0.2%
| | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t… | Aug 24, 2026 | Sep 3, 2026 |
| | CVE-2026-12554 | HPE | medium | — | 0.2%
| | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t… | Aug 24, 2026 | Sep 3, 2026 |
| | CVE-2026-19685 | Red Hat | high | 7.1 | 0.1%
| | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path d… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-71366 | Red Hat | high | 7.7 | 0.3%
| ✓ Fix | A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. … | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-71364 | Red Hat | high | 7.2 | 1.2%
| ✓ Fix | A path traversal vulnerability was found in AWX's project archive extraction. The project_archive ac… | Aug 24, 2026 | Aug 24, 2026 |
| | CVE-2026-17033 | Grafana | medium | 6.8 | 0.2%
| | An authenticated attacker with Editor access or alert.instances.external:write can submit an externa… | Aug 24, 2026 | Aug 31, 2026 |