Vulnerabilities in RED HAT

2,131 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-12894HIGHIo.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engineEPSS 0.4%CVE-2026-84267MEDIUMGvfs: sftp: uninitialized heap disclosure in read_string()EPSS 0.4%CVE-2023-43788MEDIUMLibxpm: out of bounds read in xpmcreatexpmimagefrombuffer()EPSS 0.4%CVE-2025-5918LOWLibarchive: reading past eof may be triggered for piped file streamsEPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2024-2494MEDIUMLibvirt: negative g_new0 length can lead to unbounded memory allocationEPSS 0.4%CVE-2026-53701MEDIUMGstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parserEPSS 0.4%CVE-2026-1467MEDIUMLibsoup: libsoup: http header injection via specially crafted urls when an http proxy is configuredEPSS 0.4%CVE-2026-4633LOWKeycloak: keycloak: user enumeration via differential error messagesEPSS 0.4%CVE-2020-1737HIGHA flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip moEPSS 0.4%CVE-2024-11218HIGHPodman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfileEPSS 0.4%CVE-2017-2663HIGHIt was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and cEPSS 0.4%CVE-2026-66782MEDIUMSubmariner-operator: operator clusterrole grants cluster-wide create/update on all configmapsEPSS 0.4%CVE-2026-75887HIGHOpenshift/console: openshift/console: unauthenticated path traversal in i18n locale handlerEPSS 0.4%CVE-2026-95619HIGHGcc: libstdc++ integer overflow in `new` operatorEPSS 0.4%CVE-2025-2786MEDIUMTempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operatorEPSS 0.4%CVE-2026-96275HIGHFlatpak: flatpak: arbitrary write access as root via extra-data extractionEPSS 0.4%CVE-2020-1739LOWA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svEPSS 0.4%CVE-2026-16529HIGHPcp: pcp: denial of service due to signed integer overflowEPSS 0.4%CVE-2023-38252MEDIUMW3m: out of bounds read in strnew_size() at w3m/str.cEPSS 0.4%