Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-59090 A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user … Enterprise Linux No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-16442 A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-16443 A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-58016 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo… Enterprise Linux 2.88.1+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check … Openshift Container Platform 4.21.0+ Fix from $2,3002026-05-28 CRITICAL 9.0 CVE-2026-4480EPSS 14% A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print… Openshift Container Platform 4.2.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-42010 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch… Hardened Images Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-34000 A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()… Enterprise Linux Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.1 CVE-2026-34002 A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a… Enterprise Linux Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.1 CVE-2026-33845 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass… Openshift Container Platform Mitigation only Fix from $2,3002026-04-30 CRITICAL 9.9 CVE-2026-5483 A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows… Openshift Ai 2.16.4 / 2.25.4+ Fix from $2,3002026-04-10 CRITICAL 9.1 CVE-2026-28369 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28367 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28368 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-1709EPSS 5% A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.… Enterprise Linux Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.6 CVE-2025-12543 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr… Build Of Apache Camel 2.2.39 / 2.3.21+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-14087 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti… Enterprise Linux 2.86.3+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2024-7012 An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-7923 An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.3 CVE-2024-1485 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i… Openshift 0.0.0-20240206+ Fix from $2,3002024-02-14 CRITICAL 9.1 CVE-2023-6394 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati… Build Of Quarkus 3.6.0+ Fix from $2,3002023-12-09 CRITICAL 9.8 CVE-2023-3961 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory… Storage 4.17.12 / 4.18.8+ Fix from $2,3002023-11-03 CRITICAL 9.8 CVE-2022-4039 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This … Single Sign On Mitigation only Fix from $2,3002023-09-22 CRITICAL 9.1 CVE-2022-3874 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm… Satellite Mitigation only Fix from $2,3002023-09-22 CRITICAL 9.1 CVE-2023-0118 An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on … Satellite 6.13.3+ Fix from $2,3002023-09-20 CRITICAL 9.1 CVE-2023-0462 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste… Satellite 3.8.0+ Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-0923 A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making … Openshift Data Science 1.22.1-3+ Fix from $2,3002023-09-15 CRITICAL 9.8 CVE-2023-2319 It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix… Enterprise Linux High Availability Mitigation only Fix from $2,3002023-05-17 CRITICAL 9.1 CVE-2022-3782EPSS 6% keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a… Keycloak Mitigation only Fix from $2,3002023-01-13 CRITICAL 9.8 CVE-2022-4116EPSS 33% A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to… Build Of Quarkus 2.13.5 / 2.14.2+ Fix from $2,3002022-11-22