Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Build Of Keycloak HIGH 7.2
CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…

No fix yet
Fix from $1,950 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 5.4
CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 5.4
CVE-2026-18218

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak HIGH 8.1
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak MEDIUM 6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak MEDIUM 5.5
CVE-2026-18201

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w…

No fix yet
Fix from $1,600 2026-07-29
Cluster Logging Operator MEDIUM 6.8
CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 5.5
CVE-2026-26104

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux HIGH 7.1
CVE-2026-26103

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut…

Mitigation only
Fix from $1,950 2026-02-25
3scale Api Management Platform MEDIUM 5.3
CVE-2024-9671

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…

Mitigation only
Fix from $1,600 2024-10-09
Build Of Quarkus CRITICAL 9.1
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…

Fix: 3.6.0+
Fix from $2,300 2023-12-09
Apicast HIGH 7.5
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…

Fix: 2.12.2 / 2.13.2+
Fix from $1,950 2023-09-27
Openshift Data Science CRITICAL 9.8
CVE-2023-0923

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …

Fix: 1.22.1-3+
Fix from $2,300 2023-09-15
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
3scale HIGH 7.5
CVE-2021-3814

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b…

Fix: 2.11.0+
Fix from $1,950 2022-03-25
Libvirt MEDIUM 6.5
CVE-2020-10701

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec…

Fix: 6.2.0+
Fix from $1,600 2021-05-27
Certification CRITICAL 9.1
CVE-2018-10866

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $2,300 2021-05-26
Certification HIGH 7.5
CVE-2018-10865

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $1,950 2021-05-26
Data Grid MEDIUM 6.5
CVE-2020-25711

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When …

Fix: 11.0.6+
Fix from $1,600 2020-12-03
Ansible HIGH 7.1
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-24
Enterprise Linux HIGH 7.1
CVE-2019-14822

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another…

Fix: 1.5.22+
Fix from $1,950 2019-11-25
Libvirt HIGH 7.8
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10161

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-07-30
Undertow HIGH 7.5
CVE-2019-10184

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through reque…

Fix: 2.0.23+
Fix from $1,950 2019-07-25
Rkt HIGH 7.7
CVE-2019-10145

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp…

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Rkt HIGH 7.7
CVE-2019-10147

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by …

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Libvirt MEDIUM 5.4
CVE-2019-3886

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest a…

Fix: 5.3.0+
Fix from $1,600 2019-04-04
Virtualization HIGH 8.1
CVE-2019-3879

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission …

Fix: 4.3.2.1+
Fix from $1,950 2019-03-25
Ansible Tower MEDIUM 5.5
CVE-2019-3835

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou…

No fix yet
Fix from $1,600 2019-03-25