Vulnerabilidades en Red Hat

2125 resultados
Análisis Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-4887MEDIUMGimp: gimp:memory disclosure and denial of service via specially crafted pcx imageEPSS 0.5%CVE-2024-4540HIGHKeycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookieEPSS 0.5%CVE-2025-32051MEDIUMLibsoup: segmentation fault when parsing malformed data uriEPSS 0.5%CVE-2024-3056HIGHPodman: kernel: containers in shared ipc namespace are vulnerable to denial of service attackEPSS 0.5%CVE-2025-14523HIGHLibsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)EPSS 0.5%CVE-2025-49521HIGHEvent-driven-ansible: template injection via git branch and refspec in eda projectsEPSS 0.5%CVE-2023-5764HIGHAnsible: template injectionEPSS 0.5%CVE-2023-5384HIGHInfinispan: credentials returned from configuration as clear textEPSS 0.5%CVE-2023-4001MEDIUMGrub2: bypass the grub password protection featureEPSS 0.5%CVE-2017-15097MEDIUMPrivilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user accoEPSS 0.5%CVE-2025-4574MEDIUMCrossbeam-channel: crossbeam-channel vulnerable to double free on dropEPSS 0.5%CVE-2023-4692HIGHGrub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code executionEPSS 0.5%CVE-2018-16859MEDIUMExecution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' paEPSS 0.5%CVE-2026-0989LOWLibxml2: unbounded relaxng include recursion leading to stack overflowEPSS 0.5%CVE-2026-18874MEDIUMVolsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscriptionEPSS 0.5%CVE-2020-1751MEDIUMAn out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtraceEPSS 0.5%CVE-2025-13033HIGHNodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflictEPSS 0.5%CVE-2025-2586HIGHOls: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustionEPSS 0.5%CVE-2010-0737—A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JEPSS 0.5%CVE-2026-75885CRITICALOpenshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpointEPSS 0.5%