Vulnerabilities in RED HAT
2,134 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2025-1118MEDIUMGrub2: commands/dump: the dump command is not in lockdown when secure boot is enabledEPSS 0.3%CVE-2023-6622MEDIUMKernel: null pointer dereference vulnerability in nft_dynset_init()EPSS 0.3%CVE-2024-8443LOWLibopensc: heap buffer overflow in openpgp driver when generating keyEPSS 0.3%CVE-2026-15801HIGHCri-o: cri-o: insufficient validation during container checkpoint restoreEPSS 0.3%CVE-2024-1488HIGHUnbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalationEPSS 0.3%CVE-2025-8283LOWNetavark: podman: netavark may resolve hostnames to unexpected hostsEPSS 0.3%CVE-2025-11060MEDIUMSurrealdb: surrealdb is vulnerable to unauthorized data exposure via live query subscriptionsEPSS 0.3%CVE-2026-0871MEDIUMOrg.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administratorsEPSS 0.3%CVE-2023-3164MEDIUMHeap-buffer-overflow in extractimagesection()EPSS 0.3%CVE-2023-38560MEDIUMGhostscript: integer overflow in pcl/pl/plfont.c:418 in pl_glyph_nameEPSS 0.3%CVE-2026-15555HIGHJboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshallerEPSS 0.3%CVE-2026-18381HIGHProject-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_addressEPSS 0.3%CVE-2024-45620LOWLibopensc: incorrect handling of the length of buffers or files in pkcs15initEPSS 0.3%CVE-2023-3019MEDIUMQemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()EPSS 0.3%CVE-2025-8415MEDIUMCryostat: authentication bypass if network policies are disabledEPSS 0.3%CVE-2026-3429MEDIUMOrg.keycloak.services.resources.account: improper access control leading to mfa deletion and account takeover in keycloak account rest apiEPSS 0.3%CVE-2026-18206LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching bypassEPSS 0.3%CVE-2026-90959HIGHPulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theftEPSS 0.3%CVE-2026-16071MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundaryEPSS 0.3%CVE-2026-8922MEDIUMOrg.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: security flaw in org.keycloak/keycloak-servicesEPSS 0.3%