Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Build Of Keycloak MEDIUM 5.4
CVE-2026-18211

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security…

No fix yet
Fix from $1,600 2026-07-31
Build Of Apache Camel CRITICAL 9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…

Fix: 2.2.39 / 2.3.21+
Fix from $2,300 2026-01-07
Ceph HIGH 7.5
CVE-2024-47866

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put…

Fix: after 19.2.3
Fix from $1,950 2025-11-12
Enterprise Linux HIGH 7.5
CVE-2024-6239

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed inp…

Fix: 24.06.0+
Fix from $1,950 2024-06-21
Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Software Collections HIGH 8.6
CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbit…

Fix: 1.19.0+
Fix from $1,950 2023-03-06
Openshift MEDIUM 6.3
CVE-2023-0229

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged …

Mitigation only
Fix from $1,600 2023-01-26
Fedora Coreos MEDIUM 5.5
CVE-2022-3675

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the…

Fix: 37.20221031.1.0+
Fix from $1,600 2022-11-03
3scale Api Management HIGH 8.8
CVE-2022-1414

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s…

Mitigation only
Fix from $1,950 2022-10-19
Virtualization HIGH 8.6
CVE-2014-0144

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/bu…

Patch available
Fix from $1,950 2022-09-29
Jboss Data Grid HIGH 8.8
CVE-2022-1271

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a…

Fix: 1.12 / 5.2.5+
Fix from $1,950 2022-08-31
Keycloak MEDIUM 5.3
CVE-2021-3754

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus…

Mitigation only
Fix from $1,600 2022-08-26
Openshift HIGH 8.1
CVE-2021-4125

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…

Fix: 4.6.52 / 4.7.40+
Fix from $1,950 2022-08-24
Ansible Runner HIGH 7.8
CVE-2021-4041

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to pa…

Fix: 2.1.0+
Fix from $1,950 2022-08-24
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Openshift Api Management MEDIUM 5.4
CVE-2021-3442

A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s…

Mitigation only
Fix from $1,600 2022-08-22
Openshift HIGH 7.5
CVE-2021-4047

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff…

Mitigation only
Fix from $1,950 2022-04-11
Ansible Automation Platform HIGH 7.1
CVE-2021-3583

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…

Fix: 2.9.23 / 3.7.0+
Fix from $1,950 2021-09-22
Enterprise Linux HIGH 7.8
CVE-2021-33285

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Enterprise Linux HIGH 7.5
CVE-2021-3580

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani…

Fix: 3.7.3+
Fix from $1,950 2021-08-05
Keycloak CRITICAL 9.6
CVE-2021-20195

A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …

Fix: 12.0.3+
Fix from $2,300 2021-05-28
Enterprise Linux MEDIUM 5.5
CVE-2021-30501

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abor…

Patch available
Fix from $1,600 2021-05-27
Openshift Container Platform MEDIUM 5.5
CVE-2021-20297

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat …

Fix: 1.30.0+
Fix from $1,600 2021-05-26
Enterprise Linux HIGH 7.5
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…

Fix: 1.0.1+
Fix from $1,950 2021-05-21
Ceph MEDIUM 5.3
CVE-2021-3531

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes…

Fix: 14.2.21+
Fix from $1,600 2021-05-18
Ceph MEDIUM 6.5
CVE-2021-3524

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …

Fix: 14.2.21+
Fix from $1,600 2021-05-17
Openshift Container Platform HIGH 7.1
CVE-2020-27833

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c…

Fix: after 4.7
Fix from $1,950 2021-05-14
Enterprise Linux MEDIUM 5.5
CVE-2020-27824

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input t…

Fix: 2.4.0+
Fix from $1,600 2021-05-13
Enterprise Linux MEDIUM 6.5
CVE-2021-3482

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada…

Fix: after 0.27.3
Fix from $1,600 2021-04-08
Keycloak HIGH 7.5
CVE-2021-20222

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …

Fix: 13.0.0+
Fix from $1,950 2021-03-23