Vulnerabilities in Red Hat

1,512 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2025-13947HIGHWebkit: webkitgtk: remote user-assisted information disclosure via file drag-and-dropEPSS 0.3%CVE-2023-5972HIGHKernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.cEPSS 0.3%CVE-2024-9671MEDIUMSystem: pdf invoices of the developer users can be seen if the url is knownEPSS 0.3%CVE-2025-3576MEDIUMKrb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisionsEPSS 0.3%CVE-2026-2366LOWKeycloak: keycloak: information disclosure via authorization bypass in admin apiEPSS 0.3%CVE-2024-4029MEDIUMWildfly: no timeout for eap management interface may lead to denial of service (dos)EPSS 0.3%CVE-2020-1704HIGHAn insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in EPSS 0.3%CVE-2026-9099HIGHKeycloak: group-admin escalation to realm-adminEPSS 0.3%CVE-2026-56208HIGHLibaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap modeEPSS 0.3%CVE-2023-4194MEDIUMKernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuidEPSS 0.3%CVE-2026-1531HIGHForeman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verificationEPSS 0.3%CVE-2025-62231HIGHXorg: xmayland: value overflow in xkbsetcompatmap()EPSS 0.3%CVE-2024-7730HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()EPSS 0.3%CVE-2024-4812MEDIUMKatello: potential cross-site scripting exploit in uiEPSS 0.3%CVE-2023-5056MEDIUMSkupper-operator: privelege escalation via config mapEPSS 0.3%CVE-2023-4886MEDIUMForeman: world readable file containing secretsEPSS 0.3%CVE-2023-34318HIGHHeap-buffer-overflow in src/hcom.cEPSS 0.3%CVE-2025-49180HIGHXorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extensionEPSS 0.3%CVE-2013-0266MEDIUMPuppetlabs-cinder: packstack: openstack: puppetlabs-cinder: information disclosure of openstack administrative passwords due to world-readable configuration files.EPSS 0.3%CVE-2026-56209HIGHLibaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijackEPSS 0.3%