Vulnerabilities in RED HAT
2,128 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2023-32255MEDIUMKernel: memory leak via ksmbd session setup request with unknown ntlmssp message typeEPSS 0.5%CVE-2026-87853HIGHSssd: sssd: idp authentication prefix comparison allows cross-user impersonationEPSS 0.5%CVE-2026-89058HIGHResteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard configEPSS 0.5%CVE-2026-89060HIGHStolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration referencesEPSS 0.5%CVE-2025-62229HIGHXorg: xmayland: use-after-free in xpresentnotify structure creationEPSS 0.5%CVE-2026-42965HIGHOpenshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validationEPSS 0.5%CVE-2025-66287HIGHWebkitgtk: processing maliciously crafted web content may lead to an unexpected process crashEPSS 0.5%CVE-2026-71473HIGHAcm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spokeEPSS 0.5%CVE-2026-50237HIGHOpenshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via projecthelmchartrepository in openshift consoleEPSS 0.5%CVE-2026-50236HIGHOpenshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift consoleEPSS 0.5%CVE-2026-13087HIGHKernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...EPSS 0.5%CVE-2023-3361HIGHS3 credentials included when exporting elyra notebookEPSS 0.5%CVE-2026-3009HIGHOrg.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)EPSS 0.5%CVE-2025-6019HIGHLibblockdev: lpe from allow_active to root in libblockdev via udisksEPSS 0.5%CVE-2024-6655HIGHGtk3: gtk2: library injection from cwdEPSS 0.5%CVE-2025-3360LOWGlibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid iso 8601 timestamp with g_date_time_new_from_iso8601().EPSS 0.5%CVE-2025-5372MEDIUMLibssh: incorrect return code handling in ssh_kdf() in libsshEPSS 0.5%CVE-2026-19654HIGHRsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogdEPSS 0.5%CVE-2023-33952MEDIUMKernel: vmwgfx: double free within the handling of vmw_buffer_object objectsEPSS 0.5%CVE-2023-1932MEDIUMHibernate-validator: rendering of invalid html with safehtml leads to html injection and xssEPSS 0.5%