Vulnerabilidades en RED HAT

2125 resultados
Análisis Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2024-4871MEDIUMForeman: host ssh key not being checked in remote executionEPSS 0.6%CVE-2026-84268HIGHGvfs: sftp: heap-based buffer overflow in read_reply()EPSS 0.6%CVE-2024-7143MEDIUMPulpcore: rbac permissions incorrectly assigned in tasks that create objectsEPSS 0.6%CVE-2025-4373MEDIUMGlib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unicharEPSS 0.6%CVE-2020-25655MEDIUMAn issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views EPSS 0.6%CVE-2026-76763HIGHIo.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literalsEPSS 0.6%CVE-2026-76235HIGHCockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_htmlEPSS 0.6%CVE-2018-10854MEDIUMcloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastEPSS 0.6%CVE-2026-91149HIGHCockpit: cockpit: denial of service via unbounded connection thread spawningEPSS 0.6%CVE-2026-94640HIGHRpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of serviceEPSS 0.6%CVE-2026-15565HIGHUndertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage methodEPSS 0.6%CVE-2026-18611HIGHData-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand) for db and s3 credentialsEPSS 0.6%CVE-2026-59090HIGHGimp: gimp: arbitrary code execution in psd plugin due to unsigned underflowEPSS 0.6%CVE-2026-15927MEDIUMQuay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validationEPSS 0.6%CVE-2026-59850MEDIUMLibssh: libssh: use-after-free via data callbacks on closed channelsEPSS 0.6%CVE-2023-3597MEDIUMKeycloak: secondary factor bypass in step-up authenticationEPSS 0.6%CVE-2026-24329MEDIUMWildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user.EPSS 0.6%CVE-2026-26157HIGHBusybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitizationEPSS 0.6%CVE-2024-50311MEDIUMGraphql: denial of service (dos) vulnerability via graphql batchingEPSS 0.6%CVE-2026-18949HIGHOdh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resourcesEPSS 0.6%