Where
-Infinity
0

oss-secPacemaker: Denial of Service via integer overflow in mote message decompssion (CVE-2026-10649)

redhat Enterprise Linux For Power Little Endian EusBooth: specially crafted hash can lead to invalid hmac being accepted by booth server

Risk 35
Severity
5.9
First published (updated )

ubuntu/libqbBuffer Overflow

Risk 90
Severity
9.8
First published (updated )

ClusterLabs pcsIt was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red H…

Risk 88
Severity
9.8
First published (updated )

ClusterLabs HawkAn issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the bina…

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

debian/pcsA vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Un…

Risk 69
Severity
7.8
First published (updated )

Debian Debian LinuxThe authfile directive in the booth config file is ignored, preventing use of authentication in comm…

Risk 40
Severity
6.5
First published (updated )

Debian Debian LinuxA flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired acco…

Risk 79
Severity
8.8
First published (updated )

ClusterLabs Cluster Gluestonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possi…

Risk 32
Severity
5.5
First published (updated )

ClusterLabs HawkOS Command Injection, Code Injection

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ubuntu/crmshOS Command Injection, Code Injection

Risk 72
Severity
7.8
First published (updated )

Hi All, Pacemaker is a high-availability cluster manager comprising multiple daemon processes that …

First published (updated )

redhat/pacemakerAn ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in …

Risk 80
Severity
9
First published (updated )

ClusterLabs fence-agentsIn fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py scri…

Risk 35
Severity
5.9
First published (updated )

ClusterLabs PacemakerPacemaker before 1.1.6 configure script creates temporary files insecurely

Risk 31
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/fence-agentsA flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a…

Risk 26
Severity
5
First published (updated )

redhat/libqblibqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it …

Risk 52
Severity
7.1
First published (updated )

Canonical Ubuntu LinuxUse After Free

Risk 43
Severity
7.5
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 36
Severity
6.2
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 72
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise Linux Server EusAn authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC …

Risk 72
Severity
8.8
First published (updated )

redhat/pcsInfoleak, Input Validation

Risk 43
Severity
7.5
First published (updated )

redhat/pcsPath Traversal

Risk 59
Severity
8.7
First published (updated )

ClusterLabs PacemakerPacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial…

Risk 43
Severity
7.5
First published (updated )

redhat/pcsXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject FedoraSession fixation vulnerability in pcsd in pcs before 0.9.157.

Risk 60
Severity
8.1
First published (updated )

Fedoraproject FedoraCSRF

Risk 79
Severity
8.8
First published (updated )

redhat Enterprise Linux High AvailabilityPacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users …

Risk 52
Severity
7.5
First published (updated )

redhat Enterprise LinuxPacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is…

Risk 23
Severity
4.3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203