Vulnerabilidades em Red Hat

2.114 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2025-2559MEDIUMOrg.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloakEPSS 0.7%CVE-2024-8768HIGHVllm: a completions api request with an empty prompt will crash the vllm api server.EPSS 0.7%CVE-2019-3891MEDIUMIt was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the CanEPSS 0.7%CVE-2019-3845HIGHA lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before EPSS 0.7%CVE-2026-28369HIGHUndertow: undertow: request smuggling via malformed http request headersEPSS 0.7%CVE-2019-10146MEDIUMA Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service EPSS 0.7%CVE-2026-13087HIGHKernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...EPSS 0.7%CVE-2025-6395MEDIUMGnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()EPSS 0.7%CVE-2019-3876MEDIUMA flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to EPSS 0.7%CVE-2024-12401MEDIUMCert-manager: potential dos when parsing specially crafted pem inputsEPSS 0.7%CVE-2024-6508HIGHOpenshift-console: oauth2 insufficient state parameter entropyEPSS 0.7%CVE-2023-39176MEDIUMKernel: ksmbd: transform header out-of-bounds read information disclosure vulnerabilityEPSS 0.7%CVE-2025-4945LOWLibsoup: integer overflow in cookie expiration date handling in libsoupEPSS 0.7%CVE-2023-5349MEDIUMDraw while calling getdrawinfo()EPSS 0.7%CVE-2026-14476HIGHSssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypassEPSS 0.7%CVE-2024-2698HIGHFreeipa: delegation rules allow a proxy service to impersonate any user to access another target serviceEPSS 0.7%CVE-2026-6857HIGHCamel-infinispan: camel-infinispan: remote code execution via unsafe deserializationEPSS 0.7%CVE-2024-6861HIGHForeman: foreman: oauth secret exposure via unauthenticated access to the graphql apiEPSS 0.7%CVE-2024-52616MEDIUMAvahi: avahi wide-area dns predictable transaction idsEPSS 0.7%CVE-2023-4727HIGHCa: token authentication bypass vulnerabilityEPSS 0.7%