Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-17059 A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem… Build Of Keycloak No fix yet Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-14614 A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,6002026-07-03 MEDIUM 6.5 CVE-2026-5135 A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing… Satellite 3.18.2 / 3.19.1+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-5142 A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (… Satellite 3.18.2 / 3.19.1+ Fix from $1,6002026-07-01 HIGH 7.7 CVE-2026-9099 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit… Build Of Keycloak Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.8 CVE-2026-4630 A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 HIGH 7.4 CVE-2026-32589 A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2023-38201 A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo… Enterprise Linux Patch available Fix from $1,6002023-08-25 CRITICAL 9.8 CVE-2022-1245 A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac… Keycloak 18.0.0+ Fix from $2,3002022-07-08 HIGH 7.5 CVE-2022-1949 An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr… 389 Directory Server after 2.0.0 Fix from $1,9502022-06-02 MEDIUM 6.5 CVE-2020-10779 Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch… Cloudforms Mitigation only Fix from $1,6002020-08-11