Vulnerabilities in Red Hat

2,125 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2023-39179HIGHKernel: ksmbd: read request out-of-bounds read information disclosure vulnerabilityEPSS 1.1%CVE-2024-1481MEDIUMFreeipa: specially crafted http requests potentially lead to denial of serviceEPSS 1.1%CVE-2024-12133MEDIUMLibtasn1: inefficient der decoding in libtasn1 leading to potential remote dosEPSS 1.1%CVE-2023-6927MEDIUMKeycloak: open redirect via "form_post.jwt" jarm response modeEPSS 1.1%CVE-2019-19342MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password containEPSS 1.1%CVE-2022-3596HIGHInstack-undercloud: rsync leaks information to undercloudEPSS 1.1%CVE-2025-9566HIGHPodman: podman kube play command may overwrite host filesEPSS 1.1%CVE-2023-1192MEDIUMUse-after-free in smb2_is_status_io_timeout()EPSS 1.1%CVE-2023-42670MEDIUMSamba: ad dc busy rpc multiple listener dosEPSS 1.1%CVE-2016-8631MEDIUMThe OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routesEPSS 1.1%CVE-2017-12175LOWRed Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.EPSS 1.1%CVE-2018-14658MEDIUMA flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.EPSS 1.1%CVE-2026-5680HIGHUndertow-core: undertow: denial of service via websocket permessage-deflate processingEPSS 1.1%CVE-2019-14887HIGHA flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't hoEPSS 1.1%CVE-2026-35091HIGHCorosync: corosync: denial of service and information disclosure via crafted udp packetEPSS 1.1%CVE-2023-4639HIGHUndertow: cookie smuggling/spoofingEPSS 1.1%CVE-2024-2002HIGHLibdwarf: crashes randomly on fuzzed objectEPSS 1.1%CVE-2026-9064HIGH389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)EPSS 1.1%CVE-2026-18948CRITICALFeast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry serverEPSS 1.1%CVE-2023-39418LOWPostgresql: merge fails to enforce update or select row security policiesEPSS 1.1%