Vulnerabilities in RED HAT

2,125 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2019-10213MEDIUMOpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operatorEPSS 1.0%CVE-2025-4432MEDIUMRing: some aes functions may panic when overflow checking is enabled in ringEPSS 1.0%CVE-2026-18358HIGHGnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of serviceEPSS 1.0%CVE-2023-39197MEDIUMKernel: dccp: conntrack out-of-bounds read in nf_conntrack_dccp_packet()EPSS 1.0%CVE-2026-0990MEDIUMLibxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processingEPSS 1.0%CVE-2023-6240MEDIUMKernel: marvin vulnerability side-channel leakage in the rsa decryption operationEPSS 1.0%CVE-2019-19336MEDIUMA cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters weEPSS 1.0%CVE-2023-1584HIGHQuarkus-oidc: id and access tokens leak via the authorization code flowEPSS 1.0%CVE-2026-18649HIGHGstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloadersEPSS 1.0%CVE-2023-0462HIGHArbitrary code execution through yaml global parametersEPSS 1.0%CVE-2019-10177MEDIUMA stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user inEPSS 1.0%CVE-2026-76578CRITICALIpa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aciEPSS 1.0%CVE-2025-32906HIGHLibsoup: out of bounds reads in soup_headers_parse_request()EPSS 1.0%CVE-2026-44189HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filenameEPSS 1.0%CVE-2022-3916MEDIUMKeycloak: session takeover with oidc offline refreshtokensEPSS 1.0%CVE-2024-11734MEDIUMOrg.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security headersEPSS 1.0%CVE-2023-6291HIGHKeycloak: redirect_uri validation bypassEPSS 0.9%CVE-2026-84218HIGHOrg.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)EPSS 0.9%CVE-2025-32911CRITICALLibsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" ghashtable valueEPSS 0.9%CVE-2018-10934MEDIUMA cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles tEPSS 0.9%