Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-59090
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …
Enterprise Linux
No fix yet
CRITICAL 9.8
CVE-2026-16442
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.1
CVE-2026-16443
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.1
CVE-2026-58016
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo…
Enterprise Linux
2.88.1+
CRITICAL 9.8
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …
Openshift Container Platform
4.21.0+
CRITICAL 9.0
CVE-2026-4480EPSS 14%
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…
Openshift Container Platform
4.2.1+
CRITICAL 9.8
CVE-2026-42010
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…
Hardened Images
Mitigation only
CRITICAL 9.1
CVE-2026-34000
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…
Enterprise Linux
Mitigation only
CRITICAL 9.1
CVE-2026-34002
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…
Enterprise Linux
Mitigation only
CRITICAL 9.1
CVE-2026-33845
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…
Openshift Container Platform
Mitigation only
CRITICAL 9.9
CVE-2026-5483
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…
Openshift Ai
2.16.4 / 2.25.4+
CRITICAL 9.1
CVE-2026-28369
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28367
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.1
CVE-2026-28368
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…
Build Of Apache Camel Hawtio
Mitigation only
CRITICAL 9.8
CVE-2026-1709EPSS 5%
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.…
Enterprise Linux
Mitigation only
CRITICAL 9.6
CVE-2025-12543
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…
Build Of Apache Camel
2.2.39 / 2.3.21+
CRITICAL 9.8
CVE-2025-14087
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti…
Enterprise Linux
2.86.3+
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
CRITICAL 9.3
CVE-2024-1485
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…
Openshift
0.0.0-20240206+
CRITICAL 9.1
CVE-2023-6394
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…
Build Of Quarkus
3.6.0+
CRITICAL 9.8
CVE-2023-3961
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…
Storage
4.17.12 / 4.18.8+
CRITICAL 9.8
CVE-2022-4039
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …
Single Sign On
Mitigation only
CRITICAL 9.1
CVE-2022-3874
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…
Satellite
Mitigation only
CRITICAL 9.1
CVE-2023-0118
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …
Satellite
6.13.3+
CRITICAL 9.1
CVE-2023-0462
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…
Satellite
3.8.0+
CRITICAL 9.8
CVE-2023-0923
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …
Openshift Data Science
1.22.1-3+
CRITICAL 9.8
CVE-2023-2319
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…
Enterprise Linux High Availability
Mitigation only
CRITICAL 9.1
CVE-2022-3782EPSS 6%
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…
Keycloak
Mitigation only
CRITICAL 9.8
CVE-2022-4116EPSS 33%
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to…
Build Of Quarkus
2.13.5 / 2.14.2+