Vulnerabilities in RED HAT

2,124 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2023-5408HIGHOpenshift: modification of node role labelsEPSS 1.1%CVE-2024-12133MEDIUMLibtasn1: inefficient der decoding in libtasn1 leading to potential remote dosEPSS 1.1%CVE-2023-39179HIGHKernel: ksmbd: read request out-of-bounds read information disclosure vulnerabilityEPSS 1.1%CVE-2024-1481MEDIUMFreeipa: specially crafted http requests potentially lead to denial of serviceEPSS 1.1%CVE-2023-6927MEDIUMKeycloak: open redirect via "form_post.jwt" jarm response modeEPSS 1.1%CVE-2019-19342MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password containEPSS 1.1%CVE-2022-3596HIGHInstack-undercloud: rsync leaks information to undercloudEPSS 1.1%CVE-2023-1192MEDIUMUse-after-free in smb2_is_status_io_timeout()EPSS 1.1%CVE-2023-42670MEDIUMSamba: ad dc busy rpc multiple listener dosEPSS 1.1%CVE-2016-8631MEDIUMThe OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routesEPSS 1.1%CVE-2017-12175LOWRed Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.EPSS 1.1%CVE-2018-14658MEDIUMA flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.EPSS 1.1%CVE-2026-5680HIGHUndertow-core: undertow: denial of service via websocket permessage-deflate processingEPSS 1.1%CVE-2019-14887HIGHA flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't hoEPSS 1.1%CVE-2026-35091HIGHCorosync: corosync: denial of service and information disclosure via crafted udp packetEPSS 1.1%CVE-2023-4639HIGHUndertow: cookie smuggling/spoofingEPSS 1.1%CVE-2024-2002HIGHLibdwarf: crashes randomly on fuzzed objectEPSS 1.1%CVE-2026-9064HIGH389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)EPSS 1.1%CVE-2025-9566HIGHPodman: podman kube play command may overwrite host filesEPSS 1.1%CVE-2026-18948CRITICALFeast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry serverEPSS 1.1%