Vulnerabilities in RED HAT
2,136 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-11986MEDIUMKeycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloakEPSS 0.3%CVE-2024-52337MEDIUMTuned: improper sanitization of `instance_name` parameter of the `instance_create()` methodEPSS 0.3%CVE-2026-11800HIGHOrg.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusionEPSS 0.3%CVE-2023-32253MEDIUMKernel: deadlock in ksmbd_find_crypto_ctx()EPSS 0.3%CVE-2026-16530MEDIUMPcp: pcp: remote denial of service and information leakageEPSS 0.3%CVE-2026-7309MEDIUMOpenshift-controller-manager: openshift container platform: information disclosure via environment variable injectionEPSS 0.3%CVE-2026-84470MEDIUMAutomation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypassEPSS 0.3%CVE-2025-12110MEDIUMKeycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was removedEPSS 0.3%CVE-2026-54100HIGHWindows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theftEPSS 0.3%CVE-2023-4959MEDIUMQuay: cross-site request forgery (csrf) on config-editor pageEPSS 0.3%CVE-2023-7192MEDIUMKernel: refcount leak in ctnetlink_create_conntrack()EPSS 0.3%CVE-2024-9355MEDIUMGolang-fips: golang fips zeroed bufferEPSS 0.3%CVE-2025-14778MEDIUMKeycloak: incorrect ownership checks in /uma-policy/EPSS 0.3%CVE-2026-16473MEDIUMSbc: sbc: heap out-of-bounds read via crafted sbc audio frameEPSS 0.3%CVE-2024-0841MEDIUMKernel: hugetlbfs: null pointer dereference in hugetlbfs_fill_super functionEPSS 0.3%CVE-2026-59089MEDIUMGimp: gimp: denial of service via integer overflow in playstation tim loaderEPSS 0.3%CVE-2024-9683MEDIUMQuay: quay allows successful authentication with trucated version of the passwordEPSS 0.3%CVE-2026-16089MEDIUMKeycloak-services: keycloak-services: authorization codes can be retargeted to another client sessionEPSS 0.3%CVE-2020-10782MEDIUMAn exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be EPSS 0.3%CVE-2026-83596HIGHWebkitgtk: validate the full featurelist array once in opentypeverticaldata findfeatureEPSS 0.3%