Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2025-26601HIGHXorg: xwayland: use-after-free in syncinittrigger()EPSS 0.4%CVE-2025-26600HIGHXorg: xwayland: use-after-free in playreleasedevents()EPSS 0.4%CVE-2024-7318MEDIUMKeycloak-core: one time passcode (otp) is valid longer than expiration timeseverityEPSS 0.4%CVE-2026-19879MEDIUMIo.undertow/undertow: undertow: http response header integrity issue due to character truncationEPSS 0.4%CVE-2025-26594HIGHX.org: xwayland: use-after-free of the root cursorEPSS 0.4%CVE-2024-4027HIGHUndertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacksEPSS 0.4%CVE-2026-9087MEDIUMKeycloak: cross-session email verification proof not bound to upstream identity in first-broker-loginEPSS 0.4%CVE-2024-9675HIGHBuildah: buildah allows arbitrary directory mountEPSS 0.4%CVE-2026-87875MEDIUMCups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length boundEPSS 0.4%CVE-2024-8007HIGHOpenstack-tripleo-common: rhosp director disables tls verification for registry mirrorsEPSS 0.4%CVE-2026-4366MEDIUMKeycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloakEPSS 0.4%CVE-2025-1057MEDIUMKeylime: keylime registrar dos due to incompatible database entry handlingEPSS 0.4%CVE-2026-66339MEDIUMLibsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnelsEPSS 0.4%CVE-2026-94213MEDIUMKeycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identityEPSS 0.4%CVE-2026-14251HIGHGitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dosEPSS 0.4%CVE-2026-18572MEDIUMKeycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributesEPSS 0.4%CVE-2026-18942MEDIUMFeast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalationEPSS 0.4%CVE-2024-43167LOWUnbound: null pointer dereference in unboundEPSS 0.4%CVE-2024-7383HIGHLibnbd: nbd server improper certificate validationEPSS 0.4%CVE-2024-28835MEDIUMGnutls: potential crash during chain building/verificationEPSS 0.4%