Vulnerabilities in RED HAT

2,134 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-14614MEDIUMKeycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresourceEPSS 0.3%CVE-2026-7500MEDIUMOrg.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabledEPSS 0.3%CVE-2026-85534MEDIUMLibsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body readEPSS 0.3%CVE-2021-4037MEDIUMKernel: security regression for cve-2018-13405EPSS 0.3%CVE-2026-94218LOWKeycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpointEPSS 0.3%CVE-2023-3428MEDIUMImagemagick: heap-buffer-overflow in coders/tiff.cEPSS 0.3%CVE-2026-18207MEDIUMKeycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matchingEPSS 0.3%CVE-2024-56826MEDIUMOpenjpeg: heap buffer overflow in bin/common/color.cEPSS 0.3%CVE-2026-16442HIGHKeycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restrictionEPSS 0.3%CVE-2023-6679MEDIUMKernel: null pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.cEPSS 0.3%CVE-2026-18203MEDIUMKeycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixesEPSS 0.3%CVE-2026-75939HIGHOpenshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumedEPSS 0.3%CVE-2024-43168MEDIUMUnbound: heap-buffer-overflow in unboundEPSS 0.3%CVE-2026-84713MEDIUMAutomation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracleEPSS 0.3%CVE-2024-45618LOWLibopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15initEPSS 0.3%CVE-2026-74241MEDIUMQuay: ldap referral filter injection in quay external ldap authenticationEPSS 0.3%CVE-2025-60018MEDIUMGlib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificate_openssl_get_property()"EPSS 0.3%CVE-2019-19339MEDIUMIt was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the EPSS 0.3%CVE-2025-10044MEDIUMKeycloak: keycloak error_description injection on error pagesEPSS 0.3%CVE-2026-1035LOWOrg.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race conditionEPSS 0.3%