Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-18651
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t…
Directory Server
No fix yet
HIGH 8.1
CVE-2026-18215
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove…
Build Of Keycloak
No fix yet
HIGH 7.8
CVE-2026-12112
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad…
Satellite
Mitigation only
HIGH 7.5
CVE-2026-46579
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…
Openshift Container Platform
Mitigation only
MEDIUM 5.4
CVE-2025-3910
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven…
Build Of Keycloak
26.0.11+
MEDIUM 5.3
CVE-2024-9683
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…
Quay
Mitigation only
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2024-6535
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…
Service Interconnect
Mitigation only
HIGH 8.8
CVE-2023-6787
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…
Build Of Keycloak
22.0.10 / 24.0.3+
MEDIUM 5.5
CVE-2023-4641
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …
Codeready Linux Builder
Mitigation only
MEDIUM 6.6
CVE-2023-40660
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi…
Enterprise Linux
after 0.23.0
HIGH 7.5
CVE-2023-0813
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…
Network Observability
Mitigation only
MEDIUM 5.0
CVE-2023-0264
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob…
Keycloak
7.6.2 / 18.0.6+
MEDIUM 6.5
CVE-2023-0105
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker …
Keycloak
Mitigation only
HIGH 7.5
CVE-2021-3632
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered…
Keycloak
7.4.9 / 15.1.0+
MEDIUM 6.5
CVE-2021-3979
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo…
Ceph Storage
Patch available
MEDIUM 6.8
CVE-2021-3827
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at…
Keycloak
18.0.0+
MEDIUM 6.5
CVE-2022-0996
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
389 Directory Server
No fix yet
CRITICAL 9.8
CVE-2021-31917
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…
Data Grid
11.0.12 / 12.1.4+
HIGH 7.5
CVE-2020-14380
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2021-3424
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself…
Single Sign On
Mitigation only
HIGH 7.1
CVE-2020-10709
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen…
Ansible Tower
3.5.6 / 3.6.4+
HIGH 7.2
CVE-2021-20288
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…
Ceph Storage
14.2.21+
MEDIUM 6.5
CVE-2020-27838EPSS 18%
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli…
Keycloak
13.0.0+
MEDIUM 6.5
CVE-2020-14299
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…
Jboss Enterprise Application Platform
5.0.3+
MEDIUM 6.5
CVE-2020-15136
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…
Etcd
3.3.23 / 3.4.10+
HIGH 8.8
CVE-2020-1718
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the …
Jboss Fuse
8.0.0+
HIGH 7.3
CVE-2020-8595
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact…
Openshift Service Mesh
after 1.4.3
CRITICAL 9.8
CVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
Keycloak
Mitigation only