Vulnerabilities in RED HAT

2,124 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-94184HIGHFetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)EPSS 1.2%CVE-2026-71471CRITICALAcm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container imageEPSS 1.2%CVE-2020-10755MEDIUMAn insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versionsEPSS 1.2%CVE-2020-14297MEDIUMA flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumEPSS 1.2%CVE-2020-14307MEDIUMA vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations aEPSS 1.2%CVE-2026-14544CRITICALHplip: incomplete fix for cve-2026-8631EPSS 1.2%CVE-2026-84837HIGHRpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball pathEPSS 1.2%CVE-2019-14863HIGHThere is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appliEPSS 1.2%CVE-2026-12701CRITICALPulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexportEPSS 1.2%CVE-2018-14655MEDIUMA flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary EPSS 1.2%CVE-2024-2947HIGHCockpit: command injection when deleting a sosreport with a crafted nameEPSS 1.2%CVE-2019-14843HIGHA flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be usedEPSS 1.2%CVE-2026-4802HIGHCockpit: cockpit: arbitrary command execution via crafted links in system logs uiEPSS 1.2%CVE-2023-3618MEDIUMSegmentation fault in fax3encode in libtiff/tif_fax3.cEPSS 1.2%CVE-2023-4091MEDIUMSamba: smb clients can truncate files with read-only permissionsEPSS 1.2%CVE-2020-1720LOWA flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticatedEPSS 1.2%CVE-2020-25662MEDIUMA Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initializaEPSS 1.2%CVE-2025-14905HIGH389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer overflowEPSS 1.2%CVE-2026-6857HIGHCamel-infinispan: camel-infinispan: remote code execution via unsafe deserializationEPSS 1.2%CVE-2026-52720HIGHGstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfbEPSS 1.2%