RHUI records
7 published records for vendor rhui.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-121 Stack-based Buffer Overflow1
- CWE-130 Improper Handling of Length Parameter Inconsistency1
- CWE-416 Use After Free1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-6100No exploit | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressurepython software foundation · cpython · CWE-416 | Critical9.1 | — | 0.8% | Apr 13, 2026 |
33Monitor | CVE-2026-54369No exploit | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
33Monitor | CVE-2026-54371No exploit | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrattr project · attr · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
30Monitor | CVE-2026-33846No exploit | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassemblyred hat · red hat enterprise linux 10 · CWE-130 | High7.5 | — | 1.1% | May 4, 2026 |
30Monitor | CVE-2026-4111No exploit | Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchivered hat · red hat enterprise linux 10 · CWE-835 | High7.5 | — | 0.9% | Mar 13, 2026 |
30Monitor | CVE-2026-48863No exploit | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceopensuse · libsolv · CWE-121 | High7.5 | — | 0.8% | Jul 15, 2026 |
28Monitor | CVE-2026-4786No exploit | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()python software foundation · cpython · CWE-77 | High7.0 | — | 0.5% | Apr 13, 2026 |
- CVE-2026-610036Monitor
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CriticalCVSS 9.1No exploitEPSS 1%python software foundation · cpythonApr 13, 2026
- CVE-2026-5436933Monitor
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
HighCVSS 8.4No exploitEPSS 0%acl project · aclJun 29, 2026
- CVE-2026-5437133Monitor
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
HighCVSS 8.4No exploitEPSS 0%attr project · attrJun 29, 2026
- CVE-2026-3384630Monitor
Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
HighCVSS 7.5No exploitEPSS 1%red hat · red hat enterprise linux 10May 4, 2026
- CVE-2026-411130Monitor
Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
HighCVSS 7.5No exploitEPSS 1%red hat · red hat enterprise linux 10Mar 13, 2026
- CVE-2026-4886330Monitor
Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
HighCVSS 7.5No exploitEPSS 1%opensuse · libsolvJul 15, 2026
- CVE-2026-478628Monitor
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
HighCVSS 7.0No exploitEPSS 0%python software foundation · cpythonApr 13, 2026