Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-12969
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is call…
Enterprise Linux
2.93+
MEDIUM 6.8
CVE-2026-10609
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…
Cluster Logging Operator
Mitigation only
MEDIUM 6.1
CVE-2026-55655
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2026-55653
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path…
Hardened Images
No fix yet
MEDIUM 5.9
CVE-2026-12725
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, logging of DS or DNSKEY replies contain…
Openshift Container Platform
2.93+
HIGH 8.8
CVE-2026-54099
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a …
Openshift Container Platform
4.22.1+
HIGH 8.3
CVE-2026-54100
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows …
Openshift Container Platform
after 4.22.1
MEDIUM 5.0
CVE-2026-11791
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information…
Directory Server
Mitigation only
HIGH 7.5
CVE-2026-47774
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne…
Openshift Service Mesh
1.35.11 / 1.36.7+
MEDIUM 5.4
CVE-2026-12528
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) strin…
Directory Server
Patch available
HIGH 8.1
CVE-2026-1767
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could…
Enterprise Linux
No fix yet
MEDIUM 6.1
CVE-2026-1766
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This…
Enterprise Linux
No fix yet
MEDIUM 5.6
CVE-2026-1764
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v…
Enterprise Linux
No fix yet
HIGH 7.7
CVE-2026-44495
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…
Advanced Cluster Management For Kubernetes
2.13.9 / 4.10.3+
HIGH 7.5
CVE-2025-71319
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl…
Discovery
1.4.2+
MEDIUM 6.5
CVE-2026-11789
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a craf…
Directory Server
Mitigation only
HIGH 7.5
CVE-2026-11788
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…
Directory Server
Mitigation only
MEDIUM 6.5
CVE-2026-11786
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon…
Directory Server
Mitigation only
MEDIUM 6.3
CVE-2026-11787
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a he…
Directory Server
Mitigation only
MEDIUM 6.5
CVE-2026-11611
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c…
Directory Server
Mitigation only
HIGH 7.8
CVE-2026-50264
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR…
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50258
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * Xkb…
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50259
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256]…
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50260
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those …
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50261
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a …
Enterprise Linux
21.1.23 / 24.1.12+
MEDIUM 5.5
CVE-2026-50262
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can re…
Enterprise Linux
21.1.23 / 24.1.12+
MEDIUM 5.5
CVE-2026-50263
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing …
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50256
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum …
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 7.8
CVE-2026-50257
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger…
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 8.8
CVE-2026-1784
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on…
Openshift Container Platform
Mitigation only