Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-17059

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…

No fix yet
Fix from $1,600 2026-07-24
Build Of Keycloak MEDIUM 5.4
CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-07-03
Satellite MEDIUM 6.5
CVE-2026-5135

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing…

Fix: 3.18.2 / 3.19.1+
Fix from $1,600 2026-07-01
Satellite MEDIUM 6.5
CVE-2026-5142

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (…

Fix: 3.18.2 / 3.19.1+
Fix from $1,600 2026-07-01
Build Of Keycloak HIGH 7.7
CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 8.1
CVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit…

Mitigation only
Fix from $1,950 2026-05-20
Build Of Keycloak MEDIUM 6.8
CVE-2026-4630

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Mirror Registry For Red Hat Openshift HIGH 7.4
CVE-2026-32589

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter…

Mitigation only
Fix from $1,950 2026-04-08
Enterprise Linux MEDIUM 6.5
CVE-2023-38201

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo…

Patch available
Fix from $1,600 2023-08-25
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
389 Directory Server HIGH 7.5
CVE-2022-1949

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr…

Fix: after 2.0.0
Fix from $1,950 2022-06-02
Cloudforms MEDIUM 6.5
CVE-2020-10779

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch…

Mitigation only
Fix from $1,600 2020-08-11