Vulnerability index

Browse CVEs

52 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Build Of Keycloak HIGH 8.1
CVE-2026-16102

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f…

Fix: 26.4.14 / 26.6.5+
Fix from $1,950 2026-08-05
Build Of Keycloak HIGH 8.1
CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…

No fix yet
Fix from $1,950 2026-07-16
Build Of Keycloak MEDIUM 5.4
CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-07-03
Openshift Container Platform MEDIUM 6.5
CVE-2026-1933

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, …

Fix: 4.2.2+
Fix from $1,600 2026-05-27
Build Of Keycloak MEDIUM 6.5
CVE-2026-37979

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2025-23367

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured usin…

Fix: 7.4.21 / 8.0.7+
Fix from $1,600 2025-01-30
Satellite HIGH 8.1
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…

Fix: 4.3.7-3+
Fix from $1,950 2023-10-04
3scale Api Management MEDIUM 6.3
CVE-2020-14388

A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f…

Mitigation only
Fix from $1,600 2021-06-02
3scale MEDIUM 5.4
CVE-2020-25634

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…

Fix: 2.10.0+
Fix from $1,600 2021-05-26
Openshift Container Platform HIGH 7.2
CVE-2019-10200

A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloa…

Patch available
Fix from $1,950 2021-03-19
Virtualization MEDIUM 6.5
CVE-2020-35497

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an…

Fix: after 4.4.3
Fix from $1,600 2020-12-21
Enterprise Linux MEDIUM 6.5
CVE-2020-25662

A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s…

Mitigation only
Fix from $1,600 2020-11-05
Openstack Platform CRITICAL 9.9
CVE-2020-10731

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause…

Mitigation only
Fix from $2,300 2020-07-31
Libvirt HIGH 7.8
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDe…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Satellite HIGH 7.4
CVE-2014-8183

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker wi…

Fix: 1.15.6+
Fix from $1,950 2019-08-01
Libvirt HIGH 7.8
CVE-2019-10161

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-07-30
Openstack HIGH 8.0
CVE-2019-3895

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c…

Fix: 0.9.0+
Fix from $1,950 2019-06-03
Satellite HIGH 8.0
CVE-2019-3845

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite…

Fix: 6.2+
Fix from $1,950 2019-04-11
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Cloudforms MEDIUM 6.5
CVE-2017-2664

CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl…

Fix: 5.7.3 / 5.8.1+
Fix from $1,600 2018-07-26
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Ceph Storage MEDIUM 6.5
CVE-2018-1129

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…

Patch available
Fix from $1,600 2018-07-10
Enterprise Linux Desktop HIGH 8.8
CVE-2016-9905

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and …

Fix: 45.6.0+
Fix from $1,950 2018-06-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Openstack HIGH 7.5
CVE-2016-9599

puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of T…

Mitigation only
Fix from $1,950 2018-04-24
Keycloak MEDIUM 6.5
CVE-2016-8629

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve…

Fix: 2.4.0+
Fix from $1,600 2018-03-12
Openshift HIGH 7.1
CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the U…

Mitigation only
Fix from $1,950 2018-03-09