Vulnerabilidades em RED HAT
2.125 resultadosAnálise Vexday
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-1616HIGHosim: Path Traversal via query parameters in Nginx configurationEPSS 0.5%CVE-2024-31081HIGHXorg-x11-server: heap buffer overread/data leakage in procxipassivegrabdeviceEPSS 0.5%CVE-2024-31080HIGHXorg-x11-server: heap buffer overread/data leakage in procxigetselectedeventsEPSS 0.5%CVE-2026-24330MEDIUMWildfly-core: wildfly: arbitrary file read via malicious archive deploymentEPSS 0.5%CVE-2026-4282HIGHKeycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flawEPSS 0.5%CVE-2024-2467MEDIUMPerl-crypt-openssl-rsa: side-channel attack in pkcs#1 v1.5 padding mode (marvin attack)EPSS 0.5%CVE-2025-6032HIGHPodman: podman missing tls verificationEPSS 0.5%CVE-2019-14846HIGHIn Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG EPSS 0.5%CVE-2026-6324MEDIUMLibsoup: libsoup: http request smuggling via unsigned to signed conversion errorEPSS 0.5%CVE-2026-91147MEDIUMCockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slashEPSS 0.5%CVE-2026-18663MEDIUM389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking controlEPSS 0.5%CVE-2020-1753MEDIUMA security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all EPSS 0.5%CVE-2026-18621HIGHData-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardeningEPSS 0.5%CVE-2026-55653MEDIUMOpenssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of serviceEPSS 0.5%CVE-2026-19607MEDIUMKeycloak-services: keycloak-services: broker-originated username collision causes account lockoutEPSS 0.5%CVE-2025-3416LOWRust-openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch`EPSS 0.5%CVE-2023-42753HIGHKernel: netfilter: potential slab-out-of-bound access due to integer underflowEPSS 0.5%CVE-2024-5042MEDIUMSubmariner-operator: rbac permissions can allow for the spread of node compromisesEPSS 0.5%CVE-2026-16277MEDIUMRpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()EPSS 0.5%CVE-2026-78322MEDIUMFile-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlersEPSS 0.5%