Vulnerabilidades en RED HAT
2125 resultadosAnálisis Vexday
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2025-32914HIGHLibsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.c leads to crash or exit of processEPSS 0.8%CVE-2020-1697MEDIUMIt was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not valiEPSS 0.8%CVE-2024-8676HIGHCri-o: checkpoint restore can be triggered from different namespacesEPSS 0.8%CVE-2026-7507HIGHOrg.keycloak/keycloak-services: session fixation in oidc login flow that can lead to account takeoverEPSS 0.8%CVE-2026-44190HIGHAnsible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script settingEPSS 0.8%CVE-2020-10689MEDIUMA flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user EPSS 0.8%CVE-2025-32050MEDIUMLibsoup: integer overflow in append_param_quotedEPSS 0.8%CVE-2026-93567HIGHIo.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authorityEPSS 0.7%CVE-2017-7538LOWA cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an orEPSS 0.7%CVE-2023-5215MEDIUMLibnbd: crash or misbehaviour when nbd server returns an unexpected block sizeEPSS 0.7%CVE-2025-0620MEDIUMSamba: smbd doesn't pick up group membership changes when re-authenticating an expired smb sessionEPSS 0.7%CVE-2026-15711HIGHLibsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violationEPSS 0.7%CVE-2023-6787MEDIUMKeycloak: session hijacking via re-authenticationEPSS 0.7%CVE-2019-14905HIGHA vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in AnsibEPSS 0.7%CVE-2019-14885MEDIUMA flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security aEPSS 0.7%CVE-2022-3962MEDIUMKiali: error message spoofing in kiali uiEPSS 0.7%CVE-2026-71469HIGHAcm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticated memory-exhaustion dosEPSS 0.7%CVE-2023-6841HIGHKeycloak: amount of attributes per object is not limited and it may lead to dosEPSS 0.7%CVE-2026-52722HIGHGstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handlingEPSS 0.7%CVE-2025-6193MEDIUMTrustyai-explainability: command injection via lmevaljob crEPSS 0.7%