Vulnerabilities in RED HAT
2,131 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-62147MEDIUMTempo-operator: tempo operator: query rbac bypassEPSS 0.4%CVE-2025-9572MEDIUMForeman: satellite: graphql api permission bypass leads to information disclosureEPSS 0.4%CVE-2026-66787MEDIUMLighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082EPSS 0.4%CVE-2026-15554HIGHUndertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgeryEPSS 0.4%CVE-2026-73266HIGHClusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset joinEPSS 0.4%CVE-2026-19546HIGHDbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attributeEPSS 0.4%CVE-2023-43789MEDIUMLibxpm: out of bounds read on xpm with corrupted colormapEPSS 0.4%CVE-2018-10894MEDIUMIt was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use thiEPSS 0.4%CVE-2025-12790HIGHRubygem-mqtt: rubygem-mqtt hostname validationEPSS 0.4%CVE-2026-66783MEDIUMSubmariner-operator: release workflow consumes same-org composite action via mutable @devel branch refEPSS 0.4%CVE-2026-88830HIGHBusybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflowEPSS 0.4%CVE-2025-14082LOWKeycloak-services: keycloak admin rest api: improper access control leads to sensitive role metadata information disclosureEPSS 0.4%CVE-2026-11791MEDIUM389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()EPSS 0.4%CVE-2026-81665HIGHCorosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassemblyEPSS 0.3%CVE-2026-3632LOWLibsoup: libsoup: http smuggling and server-side request forgery via malformed hostnamesEPSS 0.3%CVE-2026-1536MEDIUMLibsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headerEPSS 0.3%CVE-2026-11884MEDIUM389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculationEPSS 0.3%CVE-2023-3576MEDIUMLibtiff: memory leak in tiffcrop.cEPSS 0.3%CVE-2026-15945MEDIUMKeycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2EPSS 0.3%CVE-2026-16313HIGHSg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --exportEPSS 0.3%