Vulnerabilidades en RED HAT

2125 resultados
Análisis Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2024-50312MEDIUMGraphql: information disclosure via graphql introspection in openshiftEPSS 0.6%CVE-2026-93563HIGHIo.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dosEPSS 0.6%CVE-2023-0119MEDIUMForeman: stored cross-site scripting in host tabEPSS 0.6%CVE-2025-7493CRITICALFreeipa: idm: privilege escalation from host to domain admin in freeipaEPSS 0.6%CVE-2026-6385MEDIUMFfmpeg: ffmpeg: denial of service and potential arbitrary code execution via signed integer overflow in dvd subtitle parserEPSS 0.6%CVE-2025-14874HIGHNodemailer: nodemailer: denial of service via crafted email address headerEPSS 0.6%CVE-2026-19611HIGHWildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth foldingEPSS 0.6%CVE-2026-5136HIGHForeman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulationEPSS 0.6%CVE-2023-39327MEDIUMOpenjpeg: malicious files can cause the program to enter a large loopEPSS 0.6%CVE-2024-45497HIGHOpenshift-api: openshift-controller-manager/build: build process in openshift allows overwriting of node pull credentialsEPSS 0.6%CVE-2026-70496CRITICALSearch-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestworkEPSS 0.6%CVE-2026-16100MEDIUMKeycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error textEPSS 0.6%CVE-2024-3447MEDIUMQemu: sdhci: heap buffer overflow in sdhci_write_dataport()EPSS 0.6%CVE-2026-12856HIGHVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extensionEPSS 0.5%CVE-2026-18571MEDIUMKeycloak-services: keycloak-services: fgap v2 group assignment bypass during user creationEPSS 0.5%CVE-2026-9165HIGHStackrox: stackrox: unbounded graphql query depth allows authenticated denial of serviceEPSS 0.5%CVE-2026-15562HIGHJboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of serviceEPSS 0.5%CVE-2026-15567HIGHWildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listenerEPSS 0.5%CVE-2023-4586HIGHHotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attackEPSS 0.5%CVE-2023-4956MEDIUMQuay: clickjacking on config-editor page severityEPSS 0.5%