Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-5164
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap …
Virtio Win
Patch available
HIGH 7.5
CVE-2026-5121
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote at…
Hardened Images
Patch available
HIGH 8.2
CVE-2026-5119
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext …
Enterprise Linux
No fix yet
CRITICAL 9.1
CVE-2026-28369
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28367
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28368
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…
Build Of Apache Camel Hawtio
Mitigation only
MEDIUM 5.5
CVE-2026-4948
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, s…
Enterprise Linux
after 2.4.0
HIGH 8.1
CVE-2025-12805
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed…
Openshift Ai
No fix yet
HIGH 7.5
CVE-2026-2100
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific I…
Hardened Images
Patch available
MEDIUM 6.5
CVE-2026-2239
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Phot…
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2026-2272
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read…
Enterprise Linux
No fix yet
HIGH 8.2
CVE-2026-0966
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exp…
Hardened Images
0.11.4+
MEDIUM 6.3
CVE-2026-0964
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could…
Hardened Images
0.11.4+
MEDIUM 5.5
CVE-2026-0967
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that wh…
Enterprise Linux
after 0.11.3
HIGH 8.2
CVE-2026-2436
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` functio…
Enterprise Linux
No fix yet
HIGH 7.2
CVE-2026-3121
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…
Build Of Keycloak
Mitigation only
MEDIUM 5.5
CVE-2026-4897
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…
Openshift Container Platform
Mitigation only
HIGH 7.8
CVE-2026-4775
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile func…
Hardened Images
Mitigation only
MEDIUM 6.1
CVE-2026-4647
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue o…
Openshift Container Platform
Mitigation only
HIGH 7.5
CVE-2026-4424
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of t…
Hardened Images
Patch available
MEDIUM 6.5
CVE-2026-4426
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a fiel…
Hardened Images
Patch available
MEDIUM 5.8
CVE-2026-4366
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli…
Build Of Keycloak
Mitigation only
MEDIUM 5.3
CVE-2026-2575
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compres…
Build Of Keycloak
26.4.10+
HIGH 8.1
CVE-2026-2603
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…
Build Of Keycloak
Mitigation only
HIGH 7.7
CVE-2026-2092
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions wh…
Build Of Keycloak
Mitigation only
HIGH 7.5
CVE-2026-4271
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme…
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2026-3633
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary head…
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2026-3634
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequ…
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2026-3632
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly val…
Enterprise Linux
No fix yet
HIGH 7.1
CVE-2026-3441
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an atta…
Openshift Container Platform
Mitigation only