Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-3466EPSS 9%
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2021-20231
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Enterprise Linux
3.7.1+
CRITICAL 9.8
CVE-2021-20232
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…
Enterprise Linux
3.7.1+
CRITICAL 9.1
CVE-2020-14324
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…
Cloudforms Management Engine
5.11.7.0+
CRITICAL 9.1
CVE-2020-14325
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and…
Cloudforms
5.11.7.0+
CRITICAL 9.9
CVE-2020-10731
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause…
Openstack Platform
Mitigation only
CRITICAL 9.8
CVE-2020-1745
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final …
Undertow
after 2.0.29
CRITICAL 9.1
CVE-2019-14887
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An…
Jboss Data Grid
Mitigation only
CRITICAL 9.8
CVE-2020-1731
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password…
Keycloak Operator
8.0.2+
CRITICAL 9.8
CVE-2019-14892EPSS 6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…
Decision Manager
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2014-4657
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…
Ansible
1.5.4+
CRITICAL 9.8
CVE-2014-4678EPSS 5%
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…
Ansible
1.6.4+
CRITICAL 9.8
CVE-2014-4966
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …
Ansible
1.6.7+
CRITICAL 9.8
CVE-2014-4967
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…
Ansible
1.6.7+
CRITICAL 9.8
CVE-2014-8089
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …
Enterprise Linux
1.12.9 / 2.2.8+
CRITICAL 9.8
CVE-2020-1693
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …
Spacewalk
2.9+
CRITICAL 9.8
CVE-2014-0234
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re…
Openshift
2.1+
CRITICAL 9.8
CVE-2013-2060EPSS 6%
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…
Openshift
No fix yet
CRITICAL 9.8
CVE-2019-14906
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…
Enterprise Linux
after 2.0.9
CRITICAL 9.1
CVE-2019-14837
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …
Keycloak
8.0.0+
CRITICAL 9.8
CVE-2019-10158
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session inte…
Jboss Data Grid
after 9.4.14
CRITICAL 9.1
CVE-2019-14859
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…
Ceph Storage
0.13.3+
CRITICAL 9.8
CVE-2014-3699
eDeploy has RCE via cPickle deserialization of untrusted data
Edeploy
No fix yet
CRITICAL 9.8
CVE-2014-0175
mcollective has a default password set at install
Openshift
Mitigation only
CRITICAL 9.8
CVE-2013-2166
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Openstack
after 0.2.5
CRITICAL 9.8
CVE-2013-2167
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Openstack
after 0.2.5
CRITICAL 9.8
CVE-2019-19333
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2019-19334
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
Keycloak
Mitigation only
CRITICAL 9.8
CVE-2013-4486
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
Zanata
after 3.1.2