Vulnerabilities in Red Hat

2,125 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2019-10159MEDIUMcfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration EPSS 0.7%CVE-2023-1625HIGHInformation leak in apiEPSS 0.7%CVE-2023-5380MEDIUMXorg-x11-server: use-after-free bug in destroywindowEPSS 0.7%CVE-2019-10201HIGHIt was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML EPSS 0.7%CVE-2025-11419HIGHKeycloak: keycloak tls client-initiated renegotiation denial of serviceEPSS 0.7%CVE-2024-10492LOWKeycloak-quarkus-server: keycloak path trasversalEPSS 0.7%CVE-2023-6717MEDIUMKeycloak: xss via assertion consumer service url in saml post-binding flowEPSS 0.7%CVE-2026-52718MEDIUMGstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusionEPSS 0.7%CVE-2026-4634HIGHKeycloak: keycloak: denial of service via excessive processing of openid connect scope parametersEPSS 0.7%CVE-2026-18103MEDIUMDhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapiEPSS 0.7%CVE-2024-0822HIGHOvirt: authentication bypassEPSS 0.7%CVE-2026-78002HIGHRsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() functionEPSS 0.7%CVE-2026-71470CRITICALAcm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating saEPSS 0.7%CVE-2026-15714MEDIUMLibsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary stringEPSS 0.7%CVE-2026-72526CRITICALMulticloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotationEPSS 0.7%CVE-2026-64612HIGHLibcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed pngEPSS 0.7%CVE-2026-53705HIGHGstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer overflowEPSS 0.7%CVE-2026-93488HIGHIo.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streamsEPSS 0.7%CVE-2026-18608HIGHData-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.org */*, and clusterrole/binding crud cluster-wideEPSS 0.7%CVE-2025-10725CRITICALOpenshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster adminEPSS 0.7%