Vulnerabilidades em Red Hat

2.045 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2024-7923CRITICALPuppet-pulpcore: an authentication bypass vulnerability exists in pulpcoreEPSS 0.8%CVE-2026-0603HIGHOrg.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injectionEPSS 0.8%CVE-2023-3971HIGHController: html injection in custom login infoEPSS 0.8%CVE-2025-1634HIGHIo.quarkus:quarkus-resteasy: memory leak in quarkus resteasy classic when client requests timeoutEPSS 0.8%CVE-2026-33845HIGHGnutls: gnutls: denial of service via dtls zero-length fragmentEPSS 0.8%CVE-2025-11561HIGHSssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systemsEPSS 0.8%CVE-2023-5625MEDIUMPython-eventlet: patch regression for cve-2021-21419 in some red hat buildsEPSS 0.8%CVE-2019-14854MEDIUMOpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to DebEPSS 0.8%CVE-2026-16242CRITICALHypershift: konnectivity proxy-server accepts agent connections without validating client certificatesEPSS 0.8%CVE-2026-11774HIGH389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflowEPSS 0.8%CVE-2024-4629MEDIUMKeycloak: potential bypass of brute force protectionEPSS 0.8%CVE-2025-9900HIGHLibtiff: libtiff write-what-whereEPSS 0.8%CVE-2024-4438HIGHEtcd: incomplete fix for cve-2023-39325/cve-2023-44487 in openstack platformEPSS 0.8%CVE-2025-1247HIGHIo.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instanceEPSS 0.8%CVE-2023-6596HIGHOpenshift: incomplete fix for rapid reset (cve-2023-44487/cve-2023-39325)EPSS 0.8%CVE-2022-4039HIGHRhsso-container-image: unsecured management interface exposed to adjecent networkEPSS 0.8%CVE-2024-1102MEDIUMJberet: jberet-core logging database credentialsEPSS 0.8%CVE-2025-32990MEDIUMGnutls: vulnerability in gnutls certtool template parsingEPSS 0.8%CVE-2024-6239HIGHPoppler: pdfinfo: crash in broken documents when using -dests parameterEPSS 0.8%CVE-2024-7700MEDIUMForeman: command injection in "host init config" template via "install packages" field on foremanEPSS 0.8%