Vulnerabilidades em RED HAT

2.131 resultados
Análise Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-94001MEDIUMKeycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permissionEPSS 0.4%CVE-2025-3910MEDIUMOrg.keycloak.authentication: two factor authentication bypassEPSS 0.4%CVE-2023-32251LOWKernel: ksmbd brute force delay bypass via asynchronous requestsEPSS 0.4%CVE-2026-0968LOWLibssh: libssh: denial of service due to malformed sftp messageEPSS 0.4%CVE-2026-15416HIGHArgo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointEPSS 0.4%CVE-2026-0988LOWGlib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()EPSS 0.4%CVE-2025-13467MEDIUMOrg.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federationEPSS 0.4%CVE-2019-3864MEDIUMA vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameteEPSS 0.4%CVE-2026-8830MEDIUMKeycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulationEPSS 0.4%CVE-2026-93685MEDIUMMulticluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)EPSS 0.4%CVE-2026-15574HIGHVllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug defaultEPSS 0.4%CVE-2025-4035MEDIUMLibsoup: cookie domain validation bypass via uppercase characters in libsoupEPSS 0.4%CVE-2025-26596HIGHXorg: xwayland: heap overflow in xkbwritekeysyms()EPSS 0.4%CVE-2025-26595HIGHXorg: xwayland: buffer overflow in xkbvmodmasktext()EPSS 0.4%CVE-2024-9779HIGHOpen-cluster-management-io/ocm: cluster-manager permissions may allow a worker node to obtain service account tokensEPSS 0.4%CVE-2025-13609HIGHKeylime: keylime: registrar allows identity takeover via duplicate uuid registrationEPSS 0.4%CVE-2026-59849LOWLibssh: libssh: denial of service via automatic certificate authentication loopEPSS 0.4%CVE-2023-40546MEDIUMShim: out-of-bounds read printing error messagesEPSS 0.4%CVE-2023-5341MEDIUMImagemagick: heap use-after-free in coders/bmp.cEPSS 0.4%CVE-2026-12353MEDIUMRhcs: memory leak during https connection leads to denial of serviceEPSS 0.4%