Vulnerabilities in RED HAT

2,125 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2019-14899HIGHA vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent userEPSS 0.8%CVE-2026-2272MEDIUMGimp: gimp: memory corruption due to integer overflow in ico file handlingEPSS 0.8%CVE-2026-18355HIGH389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()EPSS 0.8%CVE-2023-4061MEDIUMWildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actorEPSS 0.8%CVE-2025-49794CRITICALLibxml: heap use after free (uaf) leads to denial of service (dos)EPSS 0.8%CVE-2026-71467HIGHAcm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofingEPSS 0.8%CVE-2026-15722HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsingEPSS 0.8%CVE-2026-7374CRITICALKubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityEPSS 0.8%CVE-2026-18618HIGHMl-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listenerEPSS 0.8%CVE-2026-18941HIGHFeast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authenticationEPSS 0.8%CVE-2025-14087MEDIUMGlib: glib: buffer underflow in gvariant parser leads to heap corruptionEPSS 0.8%CVE-2025-32913HIGHLibsoup: null pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in content-disposition headerEPSS 0.8%CVE-2026-71217HIGHIperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustionEPSS 0.8%CVE-2024-12397HIGHIo.quarkus.http/quarkus-http-core: quarkus http cookie smugglingEPSS 0.8%CVE-2025-5024HIGHGnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdusEPSS 0.8%CVE-2020-1724MEDIUMA flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal inEPSS 0.8%CVE-2026-14474HIGHSssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalationEPSS 0.8%CVE-2025-1634HIGHIo.quarkus:quarkus-resteasy: memory leak in quarkus resteasy classic when client requests timeoutEPSS 0.8%CVE-2026-48863HIGHLibsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceEPSS 0.8%CVE-2025-14242MEDIUMVsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsingEPSS 0.8%