Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-3586
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo…
Openshift Service Mesh
Mitigation only
CRITICAL 9.8
CVE-2020-27836
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…
Openshift Container Platform
Patch available
CRITICAL 9.8
CVE-2022-2457
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as th…
Process Automation Manager
7.13.2+
CRITICAL 9.1
CVE-2022-0670
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…
Ceph Storage
5.2 / 15.2.17+
CRITICAL 9.8
CVE-2022-1245
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…
Keycloak
18.0.0+
CRITICAL 9.1
CVE-2014-8164
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…
Cloudforms Management Engine
Mitigation only
CRITICAL 9.1
CVE-2013-4561
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and i…
Openshift
Patch available
CRITICAL 9.8
CVE-2021-41411
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res…
Drools
7.6.0+
CRITICAL 9.1
CVE-2022-1587
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th…
Enterprise Linux
10.40+
CRITICAL 9.8
CVE-2021-3762
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…
Clair
0.4.8 / 0.5.5+
CRITICAL 9.1
CVE-2022-0671
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
Vscode Xml
0.19.0+
CRITICAL 9.8
CVE-2021-20325
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…
Enterprise Linux
Mitigation only
CRITICAL 9.1
CVE-2021-4048
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b…
Ceph Storage
0.3.18+
CRITICAL 9.8
CVE-2021-31917
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…
Data Grid
11.0.12 / 12.1.4+
CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2021-20314
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio…
Enterprise Linux
1.2.11+
CRITICAL 9.8
CVE-2021-20236
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…
Ceph Storage
4.3.3+
CRITICAL 9.6
CVE-2021-20195
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …
Keycloak
12.0.3+
CRITICAL 9.0
CVE-2020-27832
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…
Quay
3.3.2+
CRITICAL 9.1
CVE-2018-10866
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…
Certification
Mitigation only
CRITICAL 9.1
CVE-2018-10867
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file ac…
Certification
Mitigation only
CRITICAL 9.8
CVE-2018-25011
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
Enterprise Linux
1.0.1+
CRITICAL 9.8
CVE-2018-25014
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Enterprise Linux
1.0.1+
CRITICAL 9.8
CVE-2020-36328
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check …
Enterprise Linux
1.0.1+
CRITICAL 9.8
CVE-2020-36329
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this…
Enterprise Linux
1.0.1 / 14.7+
CRITICAL 9.1
CVE-2018-25009
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
Enterprise Linux
1.0.1+
CRITICAL 9.1
CVE-2018-25010
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
Enterprise Linux
1.0.1+
CRITICAL 9.1
CVE-2018-25012
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
Enterprise Linux
1.0.1+
CRITICAL 9.1
CVE-2018-25013
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
Enterprise Linux
1.0.1+
CRITICAL 9.1
CVE-2020-36331
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne…
Enterprise Linux
1.0.1 / 14.7+