Vulnerabilities in RED HAT
2,145 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-54230HIGHAbrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwritesEPSS 0.2%CVE-2026-78323MEDIUMJss: jss: jsstrustmanager does not verify nss trust flags on ca certificatesEPSS 0.2%CVE-2025-13763MEDIUMLibopensc: opensc: multiple uses of uninitialized variableEPSS 0.2%CVE-2026-96446MEDIUMKeycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication pathEPSS 0.2%CVE-2026-88914MEDIUMGstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parserEPSS 0.2%CVE-2025-3931HIGHYggdrasil: local privilege escalation in yggdrasilEPSS 0.2%CVE-2026-16493HIGHAnsible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)EPSS 0.2%CVE-2025-4057MEDIUMActivemq-artemis-operator: amq broker operator starting credentials reuseEPSS 0.2%CVE-2026-74859MEDIUMGnome-tweaks: path traversal in theme installerEPSS 0.2%CVE-2026-79699MEDIUMPodman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directoryEPSS 0.2%CVE-2026-57966MEDIUMSpice-vdagent: path traversal in file transfer via unsanitized filenameEPSS 0.2%CVE-2025-10911MEDIUMLibxslt: use-after-free with key data stored cross-rvtEPSS 0.2%CVE-2026-48914MEDIUMQemu-kvm: heap buffer overflow in virtio-blk scsi request handlingEPSS 0.2%CVE-2026-96281MEDIUMFlatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesEPSS 0.2%CVE-2026-71221HIGHGfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemetaEPSS 0.2%CVE-2026-35094LOWLibinput: libinput: information disclosure via dangling pointer in lua plugin handlingEPSS 0.2%CVE-2026-71220HIGHGfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_editEPSS 0.2%CVE-2026-26158HIGHBusybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entriesEPSS 0.2%CVE-2026-84721MEDIUMAutomation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port (internal port-scan oracle, smtp password exfil)EPSS 0.2%CVE-2026-3195HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)EPSS 0.2%