Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.9
CVE-2026-59090

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …

No fix yet
Fix from $2,300 2026-08-10
Build Of Keycloak CRITICAL 9.8
CVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Build Of Keycloak CRITICAL 9.1
CVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Enterprise Linux CRITICAL 9.1
CVE-2026-58016

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo…

Fix: 2.88.1+
Fix from $2,300 2026-06-30
Openshift Container Platform CRITICAL 9.8
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …

Fix: 4.21.0+
Fix from $2,300 2026-05-28
Openshift Container Platform CRITICAL 9.0
CVE-2026-4480EPSS 14%

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…

Fix: 4.2.1+
Fix from $2,300 2026-05-26
Hardened Images CRITICAL 9.8
CVE-2026-42010

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…

Mitigation only
Fix from $2,300 2026-05-07
Enterprise Linux CRITICAL 9.1
CVE-2026-34000

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…

Mitigation only
Fix from $2,300 2026-05-05
Enterprise Linux CRITICAL 9.1
CVE-2026-34002

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…

Mitigation only
Fix from $2,300 2026-05-05
Openshift Container Platform CRITICAL 9.1
CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…

Mitigation only
Fix from $2,300 2026-04-30
Openshift Ai CRITICAL 9.9
CVE-2026-5483

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…

Fix: 2.16.4 / 2.25.4+
Fix from $2,300 2026-04-10
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28369

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28367

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28368

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…

Mitigation only
Fix from $2,300 2026-03-27
Enterprise Linux CRITICAL 9.8
CVE-2026-1709EPSS 5%

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.…

Mitigation only
Fix from $2,300 2026-02-06
Build Of Apache Camel CRITICAL 9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…

Fix: 2.2.39 / 2.3.21+
Fix from $2,300 2026-01-07
Enterprise Linux CRITICAL 9.8
CVE-2025-14087

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti…

Fix: 2.86.3+
Fix from $2,300 2025-12-10
Satellite CRITICAL 9.8
CVE-2024-7012

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…

Mitigation only
Fix from $2,300 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7923

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…

Mitigation only
Fix from $2,300 2024-09-04
Openshift CRITICAL 9.3
CVE-2024-1485

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…

Fix: 0.0.0-20240206+
Fix from $2,300 2024-02-14
Build Of Quarkus CRITICAL 9.1
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…

Fix: 3.6.0+
Fix from $2,300 2023-12-09
Storage CRITICAL 9.8
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…

Fix: 4.17.12 / 4.18.8+
Fix from $2,300 2023-11-03
Single Sign On CRITICAL 9.8
CVE-2022-4039

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …

Mitigation only
Fix from $2,300 2023-09-22
Satellite CRITICAL 9.1
CVE-2022-3874

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…

Mitigation only
Fix from $2,300 2023-09-22
Satellite CRITICAL 9.1
CVE-2023-0118

An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …

Fix: 6.13.3+
Fix from $2,300 2023-09-20
Satellite CRITICAL 9.1
CVE-2023-0462

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…

Fix: 3.8.0+
Fix from $2,300 2023-09-20
Openshift Data Science CRITICAL 9.8
CVE-2023-0923

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …

Fix: 1.22.1-3+
Fix from $2,300 2023-09-15
Enterprise Linux High Availability CRITICAL 9.8
CVE-2023-2319

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…

Mitigation only
Fix from $2,300 2023-05-17
Keycloak CRITICAL 9.1
CVE-2022-3782EPSS 6%

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…

Mitigation only
Fix from $2,300 2023-01-13
Build Of Quarkus CRITICAL 9.8
CVE-2022-4116EPSS 33%

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to…

Fix: 2.13.5 / 2.14.2+
Fix from $2,300 2022-11-22