Vulnerabilities in RED HAT
2,131 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-53703HIGHGstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parserEPSS 0.5%CVE-2026-53704HIGHGstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parserEPSS 0.5%CVE-2026-15573HIGHKeycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcherEPSS 0.5%CVE-2026-37978MEDIUMKeycloak: org.keycloak.services: keycloak: information disclosure via evaluate-scopes admin apiEPSS 0.5%CVE-2026-16102HIGHKeycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappersEPSS 0.5%CVE-2023-5675MEDIUMQuarkus: authorization flaw in quarkus resteasy reactive and classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties are used.EPSS 0.5%CVE-2020-1734HIGHA flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() wiEPSS 0.5%CVE-2025-3501HIGHOrg.keycloak.protocol.services: keycloak hostname verificationEPSS 0.5%CVE-2025-59088HIGHPython-kdcproxy: unauthenticated ssrf via realm‑controlled dns srvEPSS 0.5%CVE-2025-9901MEDIUMLibsoup: improper handling of http vary header in libsoup cachingEPSS 0.5%CVE-2026-1486HIGHOrg.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grantEPSS 0.5%CVE-2024-9050HIGHNetworkmanager-libreswan: local privilege escalation via leftupdownEPSS 0.5%CVE-2025-12105HIGHLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completionEPSS 0.5%CVE-2026-16104MEDIUMKeycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only adminsEPSS 0.5%CVE-2026-16745HIGHOdh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validationEPSS 0.5%CVE-2026-12706MEDIUMFfmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()EPSS 0.5%CVE-2026-16526HIGHPcp: pcp: privilege escalation to root via linux_sockets pmda vulnerabilityEPSS 0.5%CVE-2025-47711MEDIUMNbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of serviceEPSS 0.5%CVE-2023-3772MEDIUMKernel: xfrm: null pointer dereference in xfrm_update_ae_params()EPSS 0.5%CVE-2026-84269MEDIUMGvfs: afp: heap-based buffer overflow in dsi read pathEPSS 0.5%