Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-37980MEDIUMOrg.keycloak.forms.login: keycloak: keycloak: arbitrary code execution via stored cross-site scripting (xss) in organization selection login pageEPSS 0.4%CVE-2024-0232MEDIUMSqlite: use-after-free bug in jsonparseaddnodearrayEPSS 0.4%CVE-2026-74860HIGHLibxml2: double-free/uaf in libxml2 python bindingsEPSS 0.4%CVE-2025-10939LOWOrg.keycloak/keycloak-quarkus-server: unable to restrict access to the admin consoleEPSS 0.4%CVE-2023-25585MEDIUMField `file_table` of `struct module *module` is uninitializedEPSS 0.4%CVE-2026-19387HIGHGstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoderEPSS 0.4%CVE-2026-5138MEDIUMForeman: foreman: information disclosure via improper validation of nested request parametersEPSS 0.4%CVE-2020-10685MEDIUMA flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as wEPSS 0.4%CVE-2023-25584MEDIUMOut of bounds read in parse_module function in bfd/vms-alpha.cEPSS 0.4%CVE-2026-79705MEDIUMPodman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callersEPSS 0.4%CVE-2026-9796MEDIUMKeycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerabilityEPSS 0.4%CVE-2023-25588MEDIUMField `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab`EPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%CVE-2026-84499HIGHAutomation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error messageEPSS 0.4%CVE-2026-68562MEDIUMAnsible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tamperingEPSS 0.4%CVE-2024-8285MEDIUMKroxylicious: missing upstream kafka tls hostname verificationEPSS 0.4%CVE-2026-14615MEDIUMKeycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filterEPSS 0.4%CVE-2024-1657HIGHPlatform: insecure websocket used when interacting with eda serverEPSS 0.4%CVE-2026-4630MEDIUMKeycloak: keycloak: unauthorized resource access and data modification via insecure direct object referenceEPSS 0.4%CVE-2026-93834HIGHQemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escapeEPSS 0.4%