Vulnerabilidades en RED HAT
2141 resultadosAnálisis Vexday
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-19391MEDIUMInsights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archivesEPSS 0.2%CVE-2024-12369MEDIUMElytron-oidc-client: oidc authorization code injectionEPSS 0.2%CVE-2026-96445MEDIUMKeycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headersEPSS 0.2%CVE-2024-8235MEDIUMLibvirt: crash of virtinterfaced via virconnectlistinterfaces()EPSS 0.2%CVE-2025-11395MEDIUMPodman: arbitrary file write when importing oci archiveEPSS 0.2%CVE-2023-4387HIGHKernel: vmxnet3: use-after-free in vmxnet3_rq_alloc_rx_buf()EPSS 0.2%CVE-2023-39328MEDIUMOpenjpeg: denail of service via crafted image fileEPSS 0.2%CVE-2024-0607MEDIUMKernel: nf_tables: pointer math issue in nft_byteorder_eval()EPSS 0.2%CVE-2026-75032MEDIUMBluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folderEPSS 0.2%CVE-2025-49178MEDIUMXorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignoreEPSS 0.2%CVE-2026-81668MEDIUMRubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookupEPSS 0.2%CVE-2026-12491MEDIUMVllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsEPSS 0.2%CVE-2025-0750MEDIUMCri-o: cri-o path traversal in log handling functions allows arbitrary unmountingEPSS 0.2%CVE-2026-94217LOWKeycloak-services: keycloak-services: uma scope merge across resource owners via resource name collisionEPSS 0.2%CVE-2026-15556HIGHPicketlink-federation: picketlink saml 2.0 auth bypass via missing assertionsEPSS 0.2%CVE-2026-96448MEDIUMKeycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalationEPSS 0.2%CVE-2024-45783MEDIUMGrub2: fs/hfs+: refcount can be decremented twiceEPSS 0.2%CVE-2023-1386LOWQemu: 9pfs: suid/sgid bits not dropped on file writeEPSS 0.2%CVE-2025-12103MEDIUMOpenshift-ai: trusty ai grants all authenticated users to list pods in any namespaceEPSS 0.2%CVE-2026-97177MEDIUMKeycloak-services: keycloak-services: generic user update bypasses denied reset-password permissionEPSS 0.2%