Vulnerabilities in Red Hat

2,141 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-74247MEDIUMQuay: ssrf via build archive_url in quay build apiEPSS 0.2%CVE-2019-19355HIGHAn insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access EPSS 0.2%CVE-2026-13434MEDIUMVirt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabledEPSS 0.2%CVE-2026-11611MEDIUM389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditionsEPSS 0.2%CVE-2024-45777MEDIUMGrub2: grub-core/gettext: integer overflow leads to heap oob write.EPSS 0.2%CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS 0.2%CVE-2024-8235MEDIUMLibvirt: crash of virtinterfaced via virconnectlistinterfaces()EPSS 0.2%CVE-2023-4387HIGHKernel: vmxnet3: use-after-free in vmxnet3_rq_alloc_rx_buf()EPSS 0.2%CVE-2026-96445MEDIUMKeycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headersEPSS 0.2%CVE-2025-11395MEDIUMPodman: arbitrary file write when importing oci archiveEPSS 0.2%CVE-2023-39328MEDIUMOpenjpeg: denail of service via crafted image fileEPSS 0.2%CVE-2024-0607MEDIUMKernel: nf_tables: pointer math issue in nft_byteorder_eval()EPSS 0.2%CVE-2026-75032MEDIUMBluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folderEPSS 0.2%CVE-2025-49178MEDIUMXorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignoreEPSS 0.2%CVE-2026-12491MEDIUMVllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsEPSS 0.2%CVE-2026-81668MEDIUMRubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookupEPSS 0.2%CVE-2025-0750MEDIUMCri-o: cri-o path traversal in log handling functions allows arbitrary unmountingEPSS 0.2%CVE-2026-94217LOWKeycloak-services: keycloak-services: uma scope merge across resource owners via resource name collisionEPSS 0.2%CVE-2026-15556HIGHPicketlink-federation: picketlink saml 2.0 auth bypass via missing assertionsEPSS 0.2%CVE-2026-16768MEDIUMGdk-pixbuf: out-of-bounds read in ico parserEPSS 0.2%