Vulnerabilidades em RED HAT

2.141 resultados
Análise Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-97177MEDIUMKeycloak-services: keycloak-services: generic user update bypasses denied reset-password permissionEPSS 0.2%CVE-2024-45783MEDIUMGrub2: fs/hfs+: refcount can be decremented twiceEPSS 0.2%CVE-2026-96448MEDIUMKeycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalationEPSS 0.2%CVE-2023-1386LOWQemu: 9pfs: suid/sgid bits not dropped on file writeEPSS 0.2%CVE-2026-13318MEDIUMVirt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ipEPSS 0.2%CVE-2026-76648HIGHAutomation-controller: automation-controller-container: aap controller: copyapiview.post() missing read authorization check enables job template secret recoveryEPSS 0.2%CVE-2026-0598MEDIUMAnsible-lightspeed: broken object level authorization leading to cross-user ai conversation context injection in ansible lightspeed apiEPSS 0.2%CVE-2023-2680HIGHDma reentrancy issue (incomplete fix for cve-2021-3750)EPSS 0.2%CVE-2026-80110HIGHPki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpointEPSS 0.2%CVE-2026-88831MEDIUMBusybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengthsEPSS 0.2%CVE-2025-6196MEDIUMLibgepub: integer overflow in libgepub's epub archive handlingEPSS 0.2%CVE-2025-11429MEDIUMKeycloak-server: too long and not settings compliant sessionEPSS 0.2%CVE-2024-0340MEDIUMKernel: information disclosure in vhost/vhost.c:vhost_new_msg()EPSS 0.2%CVE-2025-1272HIGHKernel: secure boot does not automatically enable kernel lockdownEPSS 0.2%CVE-2026-84232MEDIUMPulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg contentEPSS 0.2%CVE-2026-71576HIGHMulticluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source() for leaf-hub identity in all status handlersEPSS 0.2%CVE-2026-80101MEDIUMGimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationEPSS 0.2%CVE-2023-5090MEDIUMKernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrsEPSS 0.2%CVE-2024-8939MEDIUMVllm: denials of service in vllm json web apiEPSS 0.2%CVE-2023-5088MEDIUMQemu: improper ide controller reset can lead to mbr overwriteEPSS 0.2%