Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-37979MEDIUMKeycloak: keycloak: information disclosure via oidc token introspection endpoint audience bypassEPSS 0.4%CVE-2025-8419MEDIUMOrg.keycloak/keycloak-services: keycloak smtp inject vulnerabilityEPSS 0.4%CVE-2026-89298MEDIUMKeycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration getEPSS 0.4%CVE-2017-2621MEDIUMAn access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory wEPSS 0.4%CVE-2026-4325MEDIUMKeycloak: keycloak: replay of action tokens via improper handling of single-use entriesEPSS 0.4%CVE-2023-40549MEDIUMShim: out-of-bounds read in verify_buffer_authenticode() malformed pe fileEPSS 0.4%CVE-2026-73198HIGHIpa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body readEPSS 0.4%CVE-2026-73197HIGHIpa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body readEPSS 0.4%CVE-2026-1180MEDIUMOrg.keycloak.protocol.oidc: blind server-side request forgery (ssrf) in keycloak oidc dynamic client registration via jwks_uriEPSS 0.4%CVE-2026-88763MEDIUMSkupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of serviceEPSS 0.4%CVE-2023-39189MEDIUMKernel: netfilter: nftables out-of-bounds read in nf_osf_match_one()EPSS 0.4%CVE-2026-12549MEDIUMLibsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserverEPSS 0.4%CVE-2026-6494MEDIUMAap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized inputEPSS 0.4%CVE-2025-1391MEDIUMKeycloak-services: improper authorization in keycloak organization mapper allows unauthorized organization claimsEPSS 0.4%CVE-2020-14332MEDIUMA flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensEPSS 0.4%CVE-2023-6270HIGHKernel: aoe: improper reference count leads to use-after-free vulnerabilityEPSS 0.4%CVE-2020-1746MEDIUMA flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 EPSS 0.4%CVE-2026-0707MEDIUMKeycloak: keycloak authorization header parsing leading to potential security control bypassEPSS 0.4%CVE-2026-17059MEDIUMKeycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filterEPSS 0.4%CVE-2026-18209LOWKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution checkEPSS 0.4%