Vulnerabilidades en Red Hat

2128 resultados
Análisis Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2023-32255MEDIUMKernel: memory leak via ksmbd session setup request with unknown ntlmssp message typeEPSS 0.5%CVE-2026-87853HIGHSssd: sssd: idp authentication prefix comparison allows cross-user impersonationEPSS 0.5%CVE-2026-89058HIGHResteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard configEPSS 0.5%CVE-2026-89060HIGHStolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration referencesEPSS 0.5%CVE-2025-62229HIGHXorg: xmayland: use-after-free in xpresentnotify structure creationEPSS 0.5%CVE-2026-42965HIGHOpenshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validationEPSS 0.5%CVE-2025-66287HIGHWebkitgtk: processing maliciously crafted web content may lead to an unexpected process crashEPSS 0.5%CVE-2026-71473HIGHAcm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spokeEPSS 0.5%CVE-2026-50237HIGHOpenshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via projecthelmchartrepository in openshift consoleEPSS 0.5%CVE-2026-50236HIGHOpenshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift consoleEPSS 0.5%CVE-2026-13087HIGHKernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...EPSS 0.5%CVE-2023-3361HIGHS3 credentials included when exporting elyra notebookEPSS 0.5%CVE-2026-3009HIGHOrg.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)EPSS 0.5%CVE-2025-6019HIGHLibblockdev: lpe from allow_active to root in libblockdev via udisksEPSS 0.5%CVE-2024-6655HIGHGtk3: gtk2: library injection from cwdEPSS 0.5%CVE-2025-3360LOWGlibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid iso 8601 timestamp with g_date_time_new_from_iso8601().EPSS 0.5%CVE-2025-5372MEDIUMLibssh: incorrect return code handling in ssh_kdf() in libsshEPSS 0.5%CVE-2026-19654HIGHRsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogdEPSS 0.5%CVE-2023-33952MEDIUMKernel: vmwgfx: double free within the handling of vmw_buffer_object objectsEPSS 0.5%CVE-2023-1932MEDIUMHibernate-validator: rendering of invalid html with safehtml leads to html injection and xssEPSS 0.5%