Vulnerabilidades em Red Hat

2.122 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2023-33952MEDIUMKernel: vmwgfx: double free within the handling of vmw_buffer_object objectsEPSS 0.5%CVE-2023-1932MEDIUMHibernate-validator: rendering of invalid html with safehtml leads to html injection and xssEPSS 0.5%CVE-2026-32591MEDIUMMirror-registry: quay: server-side request forgery in proxy cache upstream registry configurationEPSS 0.5%CVE-2026-15154MEDIUMGuardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regexEPSS 0.5%CVE-2026-9792MEDIUMKeycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisitionEPSS 0.5%CVE-2026-0992LOWLibxml2: libxml2: denial of service via crafted xml catalogsEPSS 0.5%CVE-2026-12382HIGHAap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofingEPSS 0.5%CVE-2026-9705MEDIUMKeycloak: keycloak: attacker can re-enable and take over disabled clients via registration access tokenEPSS 0.5%CVE-2026-58216MEDIUMSamba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crashEPSS 0.5%CVE-2026-74243MEDIUMQuay: unauthenticated secscan notification endpoint in quay when psk is unsetEPSS 0.5%CVE-2023-3745MEDIUMImagemagick: heap-buffer-overflow in pushcharpixel() in quantum-private.hEPSS 0.5%CVE-2026-93576HIGHIo.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)EPSS 0.5%CVE-2026-96276CRITICALFlatpak: flatpak: arbitrary write in host context via flatpak build-initEPSS 0.5%CVE-2020-27792HIGHGhostscript: heap buffer over write vulnerability in ghostscript's lp8000_print_page() in gdevlp8k.cEPSS 0.5%CVE-2025-9640MEDIUMSamba: vfs_streams_xattr uninitialized memory write possibleEPSS 0.5%CVE-2025-12801MEDIUMNfs-utils: rpc.mountd in the nfs-utils privilege escalationEPSS 0.5%CVE-2023-43786MEDIUMLibx11: stack exhaustion from infinite recursion in putsubimage()EPSS 0.5%CVE-2026-18382MEDIUMProject-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_urlEPSS 0.5%CVE-2026-1529HIGHOrg.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validationEPSS 0.5%CVE-2021-4472MEDIUMPython-mistralclient: mistral-dashboard: local file inclusion through the 'create workbook' featureEPSS 0.5%