Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2025-49177MEDIUMXorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmodeEPSS 0.4%CVE-2026-84719CRITICALAutomation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)EPSS 0.4%CVE-2024-6840MEDIUMAutomation-controller: gain access to the k8s api server via job execution with container groupEPSS 0.4%CVE-2026-18141HIGHAap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http headerEPSS 0.4%CVE-2025-1125HIGHGrub2: fs/hfs: integer overflow may lead to heap based out-of-bounds writeEPSS 0.4%CVE-2026-32589HIGHMirror-registry: quay: insecure direct object reference in blobuploadEPSS 0.4%CVE-2023-43787HIGHLibx11: integer overflow in xcreateimage() leading to a heap overflowEPSS 0.4%CVE-2026-73196MEDIUMIpa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodingEPSS 0.4%CVE-2025-5222HIGHIcu: stack buffer overflow in the srbroot::addtag functionEPSS 0.4%CVE-2026-17048MEDIUMKeycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest apiEPSS 0.4%CVE-2019-14858HIGHA vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub paramEPSS 0.4%CVE-2024-8445MEDIUM389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199)EPSS 0.4%CVE-2025-7425HIGHLibxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptrEPSS 0.4%CVE-2026-71468MEDIUMAcm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cacheEPSS 0.4%CVE-2026-16105MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpointsEPSS 0.4%CVE-2026-16106MEDIUMKeycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child rolesEPSS 0.4%CVE-2026-16456MEDIUMOdh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputyEPSS 0.4%CVE-2024-1454LOWOpensc: memory use after free in authentic driver when updating token infoEPSS 0.4%CVE-2023-2908MEDIUMLibtiff: null pointer dereference in tif_dir.cEPSS 0.4%CVE-2026-1190LOWOrg.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdataEPSS 0.4%