Vulnerabilidades em RED HAT

2.131 resultados
Análise Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2020-1733MEDIUMA race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unpriviEPSS 0.4%CVE-2026-18214MEDIUMKeycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restrictionEPSS 0.4%CVE-2026-13097HIGHIpa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastoreEPSS 0.4%CVE-2026-2708LOWLibsoup: libsoup: http request smuggling via duplicate content-length headersEPSS 0.4%CVE-2026-12547LOWLibsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switchEPSS 0.4%CVE-2025-8277LOWLibssh: memory exhaustion via repeated key exchange in libsshEPSS 0.4%CVE-2026-94000MEDIUMKeycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membershipEPSS 0.4%CVE-2026-5704MEDIUMTar: tar: hidden file injection via crafted archivesEPSS 0.4%CVE-2022-3248MEDIUMOpenshift api admission checks does not enforce "custom-host" permissionsEPSS 0.4%CVE-2026-1801MEDIUMLibsoup: libsoup: http request smuggling via malformed chunk headersEPSS 0.4%CVE-2023-39194LOWKernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()EPSS 0.4%CVE-2026-12969MEDIUMDnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validationEPSS 0.4%CVE-2020-1738LOWA flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task iEPSS 0.4%CVE-2023-6228LOWLibtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.cEPSS 0.4%CVE-2026-19130MEDIUMProvider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorizationEPSS 0.4%CVE-2024-9666MEDIUMOrg.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerabilityEPSS 0.4%CVE-2026-0976LOWOrg.keycloak/keycloak-quarkus-server: keycloak: proxy bypass due to improper handling of matrix parameters in url pathsEPSS 0.4%CVE-2024-1441MEDIUMLibvirt: off-by-one error in udevlistinterfacesbystatus()EPSS 0.4%CVE-2026-77014MEDIUMLibsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responsesEPSS 0.4%CVE-2024-10033MEDIUMAap-gateway: xss on aap-gatewayEPSS 0.4%