Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-75884CRITICALAwx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groupsEPSS 0.4%CVE-2019-14845MEDIUMA vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hosEPSS 0.4%CVE-2025-12799MEDIUMJastow: jastow cross-site scripting attack due to unsanitized uriEPSS 0.4%CVE-2026-0964MEDIUMLibssh: improper sanitation of paths received from scp serversEPSS 0.4%CVE-2026-6388CRITICALArgocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient namespace validationEPSS 0.4%CVE-2026-80179MEDIUMJwcrypto: jwcrypto: denial of service via malformed jwe tokensEPSS 0.4%CVE-2025-11065MEDIUMGithub.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructureEPSS 0.4%CVE-2025-0752HIGHEnvoyproxy: openshift service mesh envoy http header sanitization bypass leading to dos and unauthorized accessEPSS 0.4%CVE-2023-42754MEDIUMKernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()EPSS 0.4%CVE-2024-12225CRITICALIo.quarkus:quarkus-security-webauthn: quarkus webauthn unexpected authentication bypassEPSS 0.4%CVE-2026-59091HIGHGimp: gimp: multiple vulnerabilities in file format plugins via crafted image fileEPSS 0.4%CVE-2020-1736LOWA flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destEPSS 0.4%CVE-2025-26598HIGHXorg: xwayland: out-of-bounds write in createpointerbarrierclient()EPSS 0.4%CVE-2026-2377MEDIUMMirror-registry: quay: quay: server-side request forgery via log export functionalityEPSS 0.4%CVE-2025-2877MEDIUMEvent-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in edaEPSS 0.4%CVE-2026-12388MEDIUMKeycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapperEPSS 0.4%CVE-2025-26599HIGHXorg: xwayland: use of uninitialized pointer in compredirectwindow()EPSS 0.4%CVE-2019-10183LOWVirt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interactioEPSS 0.4%CVE-2026-71577MEDIUMMulticluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migrationEPSS 0.4%CVE-2026-18215MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenantEPSS 0.4%