Vulnerabilities in RED HAT

2,125 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-84486HIGHAutomation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos)EPSS 0.5%CVE-2026-18212HIGHKeycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib stateEPSS 0.5%CVE-2026-18950HIGHOdh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creationEPSS 0.5%CVE-2026-87743HIGHQuarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus http securityEPSS 0.5%CVE-2025-59089MEDIUMPython-kdcproxy: remote dos via unbounded tcp upstream bufferingEPSS 0.5%CVE-2024-3622HIGHMirror-registry: plain-text default csrf secret keyEPSS 0.5%CVE-2026-18358HIGHGnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of serviceEPSS 0.5%CVE-2025-6052LOWGlib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstringEPSS 0.5%CVE-2023-2422MEDIUMKeycloak: oauth client impersonationEPSS 0.5%CVE-2026-71225MEDIUMLibkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundariesEPSS 0.5%CVE-2026-70398CRITICALMulticloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespaceEPSS 0.5%CVE-2023-39191HIGHKernel: ebpf: insufficient stack type checks in dynptrEPSS 0.5%CVE-2026-9802MEDIUMKeycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restartEPSS 0.5%CVE-2025-32909MEDIUMLibsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.cEPSS 0.5%CVE-2023-3089HIGHOcp & fips modeEPSS 0.5%CVE-2026-12993MEDIUMApicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subsetEPSS 0.5%CVE-2026-73199MEDIUMIpa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request valueEPSS 0.5%CVE-2026-1616HIGHosim: Path Traversal via query parameters in Nginx configurationEPSS 0.5%CVE-2026-85469HIGHQuay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scopeEPSS 0.5%CVE-2025-4478MEDIUMGnome-remote-desktop: freerdp: unauthenticated rdp packet causes segfault in freerdp leading to denial of serviceEPSS 0.5%