Vulnerabilities in RED HAT
2,125 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2023-4004HIGHKernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()EPSS 0.9%CVE-2024-10451MEDIUMOrg.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build processEPSS 0.9%CVE-2013-0186—Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspeEPSS 0.9%CVE-2026-71472CRITICALAcm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_memEPSS 0.9%CVE-2012-5626—EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss PorEPSS 0.9%CVE-2026-58015MEDIUMGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveEPSS 0.9%CVE-2020-1758MEDIUMA flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using tEPSS 0.9%CVE-2023-3603LOWProcessing sftp server read may cause null dereferenceEPSS 0.9%CVE-2024-9632HIGHXorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerabilityEPSS 0.9%CVE-2023-7216MEDIUMCpio: extraction allows symlinks which enables remote command executionEPSS 0.9%CVE-2018-10884HIGHAnsible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker cEPSS 0.9%CVE-2026-9801MEDIUMKeycloak: keycloak: denial of service via malformed ldap password policy responseEPSS 0.9%CVE-2026-18951HIGHOdh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterroleEPSS 0.9%CVE-2026-23538HIGHFeast: resource exhaustion via websocket endpointEPSS 0.9%CVE-2026-3833MEDIUMGnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparisonEPSS 0.9%CVE-2023-5236MEDIUMInfinispan: circular reference on marshalling leads to dosEPSS 0.9%CVE-2026-12398HIGHGalaxy_ng: shell injection in legacy role import via unsanitized git ref namesEPSS 0.9%CVE-2026-28367HIGHUndertow: undertow: request smuggling via `\r\r\r` as a header block terminatorEPSS 0.9%CVE-2026-28368HIGHUndertow: undertow: request smuggling via inconsistent header parsingEPSS 0.9%CVE-2026-28369HIGHUndertow: undertow: request smuggling via malformed http request headersEPSS 0.9%