Vulnerabilities in RED HAT

2,125 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2022-4145MEDIUMContent spoofingEPSS 0.6%CVE-2026-59691HIGHGstreamer1-plugins-bad-free: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebufferEPSS 0.6%CVE-2017-7528MEDIUMAnsible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For headEPSS 0.6%CVE-2026-75569HIGHMce-operator-bundle: all github actions pinned by mutable tag, not commit shaEPSS 0.6%CVE-2025-32908HIGHLibsoup: denial of service on libsoup through http/2 serverEPSS 0.6%CVE-2026-15467HIGHTrustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy overrideEPSS 0.6%CVE-2018-14620MEDIUMThe OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could poEPSS 0.6%CVE-2024-1979LOWQuarkus: information leak in annotationEPSS 0.6%CVE-2024-0793HIGHKube-controller-manager: malformed hpa v1 manifest causes crashEPSS 0.6%CVE-2026-18947HIGHFeast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized full re-materializationEPSS 0.6%CVE-2025-49795HIGHLibxml: null pointer dereference leads to denial of service (dos)EPSS 0.6%CVE-2025-0604MEDIUMKeycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloakEPSS 0.6%CVE-2023-4456MEDIUMOpenshift-logging: lokistack authorisation is cached too broadlyEPSS 0.6%CVE-2023-39329MEDIUMOpenjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.cEPSS 0.6%CVE-2026-3872HIGHKeycloak: keycloak: information disclosure due to redirect_uri validation bypassEPSS 0.6%CVE-2025-2487MEDIUM389-ds-base: null pointer dereference leads to denial of serviceEPSS 0.6%CVE-2026-9704MEDIUMKeycloak: keycloak: privilege escalation due to oversized subject_token jwtEPSS 0.6%CVE-2024-8509HIGHMigration toolkit for virtualization: forklift-controller: empty bearer token may perform authenticationEPSS 0.6%CVE-2026-19389HIGHGstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds readEPSS 0.6%CVE-2023-1832MEDIUMImproper authorization check in the server componentEPSS 0.6%