Vulnerabilities in Red Hat

2,125 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2019-14855MEDIUMA flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use thisEPSS 1.1%CVE-2018-10937MEDIUMA cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to crEPSS 1.1%CVE-2023-39418LOWPostgresql: merge fails to enforce update or select row security policiesEPSS 1.1%CVE-2023-6544MEDIUMKeycloak: authorization bypassEPSS 1.1%CVE-2026-4424HIGHLibarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processingEPSS 1.1%CVE-2014-3585—redhat-upgrade-tool: Does not check GPG signatures when upgrading versionsEPSS 1.1%CVE-2024-1300MEDIUMIo.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni supportEPSS 1.1%CVE-2025-6018HIGHPam-config: lpe from unprivileged to allow_active in pamEPSS 1.1%CVE-2026-23537CRITICALFeast: unauthenticated arbitrary file writeEPSS 1.0%CVE-2023-1193MEDIUMUse-after-free in setup_async_work()EPSS 1.0%CVE-2025-2251MEDIUMOrg.jboss.eap:wildfly-ejb3: improper deserialization in jboss marshalling allows remote code executionEPSS 1.0%CVE-2022-1415HIGHDrools: unsafe data deserialization in streamutilsEPSS 1.0%CVE-2026-14180MEDIUMUndertow-core: undertow:http request smuggling via oversized chunk-size bit overlapEPSS 1.0%CVE-2026-76166MEDIUMModcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagramEPSS 1.0%CVE-2023-3758HIGHSssd: race condition during authorization leads to gpo policies functioning inconsistentlyEPSS 1.0%CVE-2024-3019HIGHPcp: exposure of the redis server backend allows remote command execution via pmproxyEPSS 1.0%CVE-2023-3966HIGHOpenvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packetEPSS 1.0%CVE-2024-9341MEDIUMPodman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go libraryEPSS 1.0%CVE-2019-10138HIGHA flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lEPSS 1.0%CVE-2024-7409HIGHQemu: denial of service via improper synchronization in qemu nbd server during socket closureEPSS 1.0%