Vulnerabilidades em Red Hat

2.114 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2020-1718HIGHA flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized accesEPSS 1.0%CVE-2025-2240HIGHSmallrye-fault-tolerance: smallrye fault toleranceEPSS 1.0%CVE-2023-3153MEDIUMService monitor mac flow is not rate limitedEPSS 1.0%CVE-2020-10712HIGHA flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry oEPSS 1.0%CVE-2026-35092HIGHCorosync: corosync: denial of service via integer overflow in join message validationEPSS 1.0%CVE-2019-10213MEDIUMOpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operatorEPSS 1.0%CVE-2025-4432MEDIUMRing: some aes functions may panic when overflow checking is enabled in ringEPSS 1.0%CVE-2023-39197MEDIUMKernel: dccp: conntrack out-of-bounds read in nf_conntrack_dccp_packet()EPSS 1.0%CVE-2023-6240MEDIUMKernel: marvin vulnerability side-channel leakage in the rsa decryption operationEPSS 1.0%CVE-2019-19336MEDIUMA cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters weEPSS 1.0%CVE-2023-1584HIGHQuarkus-oidc: id and access tokens leak via the authorization code flowEPSS 1.0%CVE-2023-0462HIGHArbitrary code execution through yaml global parametersEPSS 1.0%CVE-2026-18649HIGHGstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloadersEPSS 1.0%CVE-2019-10177MEDIUMA stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user inEPSS 1.0%CVE-2025-32906HIGHLibsoup: out of bounds reads in soup_headers_parse_request()EPSS 1.0%CVE-2022-3916MEDIUMKeycloak: session takeover with oidc offline refreshtokensEPSS 1.0%CVE-2024-11734MEDIUMOrg.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security headersEPSS 1.0%CVE-2023-6291HIGHKeycloak: redirect_uri validation bypassEPSS 0.9%CVE-2025-32911CRITICALLibsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" ghashtable valueEPSS 0.9%CVE-2018-10934MEDIUMA cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles tEPSS 0.9%